<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:09:33.526661+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326519</id>
    <title>EUVD-2026-326519</title>
    <updated>2026-10-06T18:09:33.528541+00:00</updated>
    <content>EUVD-2026-326519</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10740</id>
    <title>fkie_cve-2026-10740</title>
    <updated>2026-10-06T18:09:33.528576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets.</p>
<p>To remediate this issue, users should upgrade to v1.8.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-10740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9q54-f358-3fqf</id>
    <title>GHSA-9q54-f358-3fqf — s2n-quic has excessive memory allocation</title>
    <updated>2026-10-06T18:09:33.528611+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: s2n-quic</p>
<p>s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a single 1200-byte packet can cause approximately 9.4 MB of allocation. By repeatedly sending such packets, the resulting memory pressure could cause denial of service. No valid handshake is required.</p>
<p>Impacted versions: &lt;= v1.81.0</p>
<p>### Patches
This issue has been addressed in s2n-quic version v1.82.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.</p>
<p>### Workarounds
There is no workaround that fully mitigates this issue. Upgrading to the patched version is the recommended remediation.</p>
<p>### References
If there are any questions or comments about this advisory, contact AWS Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9q54-f358-3fqf"/>
  </entry>
</feed>
