<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:59:38.003593+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-5215</id>
    <title>EUVD-2026-5215</title>
    <updated>2026-10-06T16:59:38.076441+00:00</updated>
    <content>EUVD-2026-5215</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-5215"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-32886</id>
    <title>fkie_cve-2024-32886</title>
    <updated>2026-10-06T16:59:38.076477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulnerability is fixed in 19.0.4, 18.0.5, and 17.0.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-32886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-649x-hxfx-57j2</id>
    <title>GHSA-649x-hxfx-57j2 — Vitess vulnerable to infinite memory consumption and vtgate crash</title>
    <updated>2026-10-06T16:59:38.076511+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/vitessio/vitess, Go: vitess.io/vitess</p>
<p>### Summary</p>
<p>When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will OOM.</p>
<p>### Details</p>
<p>When running the following query, the `evalengine` will try evaluate it and runs forever.</p>
<p>```
select _utf16 0xFF
```</p>
<p>The source of the bug lies in the collation logic that we have. The bug applies to all `utf16`,  `utf32` and `ucs2` encodings.  In general, the bug is there for any encoding where the minimal byte length for a single character is more than 1 byte.</p>
<p>The decoding functions for these collations all implement logic like the following to enforce the minimal character length:</p>
<p>https://github.com/vitessio/vitess/blob/8f6cfaaa643a08dc111395a75a2d250ee746cfa8/go/mysql/collations/charset/unicode/utf16.go#L69-L71</p>
<p>The problem is that all the callers of `DecodeRune` expect progress by returning the number of bytes consumed. This means that if there's only 1 byte left in an input, it will here return still `0` and the caller(s) don't consume the character.</p>
<p>One example of such a caller is the following:</p>
<p>https://github.com/vitessio/vitess/blob/8f6cfaaa643a08dc111395a75a2d250ee746cfa8/go/mysql/collations/charset/convert.go#L73-L79</p>
<p>The logic here moves forward the pointer in the input `[]byte` but if `DecodeRune` returns `0` in case of error, it will keep running forever. The OOM happens since it keeps adding the `?` as the invalid character to the destination buffer infinitely, growing forever until it…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-649x-hxfx-57j2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-32886</id>
    <title>gsd-2024-32886</title>
    <updated>2026-10-06T16:59:38.076563+00:00</updated>
    <content>gsd-2024-32886</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-32886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-32886</id>
    <title>msrc_CVE-2024-32886 — Vitess vulnerable to infinite memory consumption and vtgate crash</title>
    <updated>2026-10-06T16:59:38.076585+00:00</updated>
    <content>msrc_CVE-2024-32886</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-32886"/>
  </entry>
</feed>
