<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T12:24:38.565837+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08784</id>
    <title>bdu:2026-08784</title>
    <updated>2026-10-04T12:24:38.590573+00:00</updated>
    <content>bdu:2026-08784</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-krane-cve-2026-54297</id>
    <title>BREW-krane-CVE-2026-54297 — Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters</title>
    <updated>2026-10-04T12:24:38.590619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: krane</p>
<p>`Faraday::NestedParamsEncoder`, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth.</p>
<p>A crafted query string such as:</p>
<p>```text
a[x][x][x][x]...[x]=1
```</p>
<p>causes Faraday to build a deeply nested Ruby `Hash` structure. The internal `dehash` routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught `SystemStackError` (`stack level too deep`), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday's nested query parsing or URL-building paths.</p>
<p>This has been patched in version 2.14.3 and backported to 1.10.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-krane-cve-2026-54297"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</id>
    <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T12:24:38.590661+00:00</updated>
    <content>certfr-2026-avi-1165</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-de16221</id>
    <title>Withdrawn: CLEANSTART-2026-DE16221 — Security fixes for CVE-2026-54171, CVE-2026-54297, CVE-2026-54522, CVE-2026-54904, CVE-2026-54905, CVE-2026-54906, ghsa…</title>
    <updated>2026-10-04T12:24:38.590678+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: ruby-fluentd-1.18</p>
<p>Multiple security vulnerabilities affect the ruby-fluentd-1.18 package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-de16221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352408</id>
    <title>EUVD-2026-352408</title>
    <updated>2026-10-04T12:24:38.590700+00:00</updated>
    <content>EUVD-2026-352408</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352408"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54297</id>
    <title>fkie_cve-2026-54297</title>
    <updated>2026-10-04T12:24:38.590711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday's nested query parsing or URL-building paths. This vulnerability is fixed in 1.10.6 and 2.14.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54297"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-98m9-hrrm-r99r</id>
    <title>GHSA-98m9-hrrm-r99r — Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters</title>
    <updated>2026-10-04T12:24:38.590737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: faraday</p>
<p>`Faraday::NestedParamsEncoder`, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth.</p>
<p>A crafted query string such as:</p>
<p>```text
a[x][x][x][x]...[x]=1
```</p>
<p>causes Faraday to build a deeply nested Ruby `Hash` structure. The internal `dehash` routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught `SystemStackError` (`stack level too deep`), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday's nested query parsing or URL-building paths.</p>
<p>This has been patched in version 2.14.3 and backported to 1.10.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-98m9-hrrm-r99r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2802</id>
    <title>OESA-2026-2802 — rubygem-faraday security update</title>
    <updated>2026-10-04T12:24:38.590764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: rubygem-faraday</p>
<p>HTTP/REST API client library

Security Fix(es):</p>
<p>Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday&amp;apos;s build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby&amp;apos;s URI#merge to combine the connection&amp;apos;s base URL with a user-supplied path. Per RFC 3986, protocol-relative URLs (e.g. //evil.com/path) are treated as network-path references that override the base URL&amp;apos;s host/authority component. This means that if any application passes user-controlled input to Faraday&amp;apos;s get(), post(), build_url(), or other request methods, an attacker can supply a protocol-relative URL like //attacker.com/endpoint to redirect the request to an arbitrary host, enabling Server-Side Request Forgery (SSRF). This vulnerability is fixed in 2.14.1.(CVE-2026-25765)</p>
<p>Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:50221</id>
    <title>RHSA-2026:50221 — Red Hat Security Advisory: Satellite 6.19.3 Async Update</title>
    <updated>2026-10-04T12:24:38.590798+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing katello: missing repository authorization in content_uploads exposes cross-product content existence python-pillow: Pillow: Denial of Service via crafted PCF font data python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files faraday: Faraday: Denial of Service via crafted nested query strings python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file nokogiri: Nokogiri: Denial of Service or Information Disclosure via invalid encoding handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:50221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54297</id>
    <title>UBUNTU-CVE-2026-54297</title>
    <updated>2026-10-04T12:24:38.590829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: ruby-faraday, Ubuntu:16.04:LTS: ruby-faraday, Ubuntu:18.04:LTS: ruby-faraday, Ubuntu:20.04:LTS: ruby-faraday, Ubuntu:22.04:LTS: ruby-faraday, Ubuntu:24.04:LTS: ruby-faraday, Ubuntu:25.10: ruby-faraday, Ubuntu:26.04:LTS: ruby-faraday</p>
<p>Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday's nested query parsing or URL-building paths. This vulnerability is fixed in 1.10.6 and 2.14.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54297"/>
  </entry>
</feed>
