<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T15:42:45.193805+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-203320</id>
    <title>EUVD-2026-203320</title>
    <updated>2026-10-08T15:42:45.242064+00:00</updated>
    <content>EUVD-2026-203320</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-203320"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-51502</id>
    <title>fkie_cve-2024-51502</title>
    <updated>2026-10-08T15:42:45.242107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. This issue has been addressed in release version 0.4.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-51502"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7vm6-qwh5-9x44</id>
    <title>GHSA-7vm6-qwh5-9x44 — loona-hpack Panic Vulnerability</title>
    <updated>2026-10-08T15:42:45.242143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: loona-hpack</p>
<p>### Summary
`loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in https://github.com/mlalic/hpack-rs/issues/11</p>
<p>### Details
The original includes a very nice description of the problem, as well as an easy-enough fix for it.</p>
<p>### PoC
The original example pretty much still applies:
```rust
use loona_hpack::Decoder;</p>
<p>pub fn main() {
    let input = &amp;[0x3f];
    let mut decoder = Decoder::new();
    let _ = decoder.decode(input);
}
```</p>
<p>### Impact
From the original:
`All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. A patched version of the crate is available on [crates.io](https://crates.io/crates/hpack-patched) under the name hpack-patched. See [Cargo's documentation on overriding dependencies](https://doc.rust-lang.org/cargo/reference/overriding-dependencies.html) for more information.`</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7vm6-qwh5-9x44"/>
  </entry>
</feed>
