<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T18:35:25.991500+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-25727</id>
    <title>CVE-2026-25727 — time affected by a stack exhaustion denial of service attack</title>
    <updated>2026-10-04T18:35:26.010654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> time-rs time</p>
<p>time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-25727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7gcf-g7xr-8hxj</id>
    <title>GHSA-7gcf-g7xr-8hxj — serde_with: KeyValueMap serialization panics on empty sequence or map entries</title>
    <updated>2026-10-04T18:35:26.010707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: serde_with</p>
<p>### Summary</p>
<p>The public `KeyValueMap` serializer assumes that each mapped element has at least one field or item to use as the map key, but it subtracts `1` from the caller-visible length before validating that assumption. An application that serializes attacker-controlled data through `#[serde_as(as = "KeyValueMap&lt;_&gt;")]` can be crashed by an empty inner sequence or map entry.</p>
<p>### Details</p>
<p>The affected public surface includes:</p>
<p>- Serialization of `#[serde_as(as = "KeyValueMap&lt;_&gt;")]` values through `serde_json::to_string` or any other Serde serializer`
- Public `KeyValueMap` conversions for sequence and map-backed entries`</p>
<p>The root cause is: The `KeyValueMap` serializer preallocating `Vec::with_capacity(len - 1)` or `Vec::with_capacity(len.unwrap_or(17) - 1)` before checking that the element actually contains the required first key field or item.</p>
<p>The vulnerable data/control flow is: attacker-controlled empty entry -&gt; `serde_json::to_string` -&gt; `KeyValueMap&lt;TAs&gt;::serialize_as` -&gt; `SeqAsMapSerializer::{serialize_seq,serialize_map}` -&gt; `Vec::with_capacity(len - 1)` or `Vec::with_capacity(len.unwrap_or(17) - 1)` -&gt; panic</p>
<p>Relevant source locations:</p>
<p>- `serde_with/src/key_value_map.rs:590`
- `serde_with/src/key_value_map.rs:599`
- `serde_with/src/key_value_map.rs:613`
- `serde_with/src/key_value_map.rs:632`
- `serde_with/src/key_value_map.rs:648`</p>
<p>### PoC</p>
<p>```rust
/*
[dependencies]
serde = {version = "*", features = ["derive"]}
serde_with = "*"
serde_json = "*"
*/</p>
<p>use serde::S…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7gcf-g7xr-8hxj"/>
  </entry>
</feed>
