<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:39:18.084484+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-di52331</id>
    <title>CLEANSTART-2026-DI52331 — Security fix for CVE-2026-73508 applied in: keycloak 26.5.7-r7</title>
    <updated>2026-10-02T13:39:18.119997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: keycloak</p>
<p>Security vulnerability affects the keycloak package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-di52331"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352262</id>
    <title>EUVD-2026-352262</title>
    <updated>2026-10-02T13:39:18.120068+00:00</updated>
    <content>EUVD-2026-352262</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73508</id>
    <title>fkie_cve-2026-73508</title>
    <updated>2026-10-02T13:39:18.120084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73508"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mfg7-5gfp-c4w3</id>
    <title>GHSA-mfg7-5gfp-c4w3 — Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names</title>
    <updated>2026-10-02T13:39:18.120111+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.netty:netty-codec-dns</p>
<p>### Summary
A memory leak can be caused in Netty's DNS codec by sending malicious DNS packets containing invalid domain names. Because the leak occurs incrementally per packet, sustained malicious requests will cause a gradual Denial of Service.</p>
<p>### Details
Inside `io.netty.handler.codec.dns.AbstractDnsRecord`, the parsed domain name string is passed to `IDN.toASCII(name)`. If the domain name contains characters that violate IDNA rules, `IDN.toASCII` throws an `IllegalArgumentException`.</p>
<p>Because this exception occurs inside the constructor before the `DnsRecord` instance can assign the buffer to its content field for later release, the ByteBuf whose reference count was incremented (or newly allocated) is never released, resulting in a direct memory leak.</p>
<p>There are several places where variants of this leak happen:
- `io.netty.handler.codec.dns.DefaultDnsRecordDecoder#decodeRecord(java.lang.String, io.netty.handler.codec.dns.DnsRecordType, int, long, io.netty.buffer.ByteBuf, int, int)` invokes `in.retainedDuplicate()` or creates a new buffer `out` when constructing `DefaultDnsRawRecord`
- `io.netty.handler.codec.dns.DnsCodecUtil#decompressDomainName` allocates a new `ByteBuf` and passes it to `encodeDomainName()`. If the decompressed domain name contains a null byte (`\0`), `encodeDomainName()` throws an `IllegalArgumentException`, leaking the newly allocated buffer.</p>
<p>### Impact
Resource Exhaustion. Any application utilizing Netty's DnsRecordDecoder (such as DnsNameResolve…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mfg7-5gfp-c4w3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0375</id>
    <title>NCSC-2026-0375 — Kwetsbaarheden verholpen in Oracle Communications</title>
    <updated>2026-10-02T13:39:18.120150+00:00</updated>
    <content>NCSC-2026-0375</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0375"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:68754</id>
    <title>RHSA-2026:68754 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.30.1 Release.</title>
    <updated>2026-10-02T13:39:18.120203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lodash: lodash: Arbitrary code execution via untrusted input in template imports postcss: PostCSS: Information disclosure and denial of service via crafted CSS input baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak linkify-it: linkify-it: Denial of Service via crafted mailto: links io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) nanoid: nanoid: Denial of Service via infinite loop in random ID generation axios: axios: Denial of Service via uncontrolled recursion in form data processing axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:68754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73508</id>
    <title>UBUNTU-CVE-2026-73508</title>
    <updated>2026-10-02T13:39:18.120285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:Pro:26.04:LTS: netty</p>
<p>Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73508"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2511</id>
    <title>WID-SEC-W-2026-2511 — Netty: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-02T13:39:18.120323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Netty ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2511"/>
  </entry>
</feed>
