<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T21:28:20.676765+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-274114</id>
    <title>EUVD-2026-274114</title>
    <updated>2026-10-08T21:28:20.746710+00:00</updated>
    <content>EUVD-2026-274114</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-274114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-3337</id>
    <title>fkie_cve-2026-3337</title>
    <updated>2026-10-08T21:28:20.746749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis.</p>
<p>The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm.</p>
<p>Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-3337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2026-0043</id>
    <title>RUSTSEC-2026-0043 — Timing Side-Channel in AES-CCM Tag Verification in AWS-LC</title>
    <updated>2026-10-08T21:28:20.746786+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: aws-lc-fips-sys</p>
<p>Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an
unauthenticated user to potentially determine authentication tag validity
via timing analysis.</p>
<p>The impacted implementations are through the EVP CIPHER API:
`EVP_aes_128_ccm`, `EVP_aes_192_ccm`, and `EVP_aes_256_ccm`.</p>
<p>Customers of AWS services do not need to take action. `aws-lc-fips-sys`
contains code from AWS-LC. Applications using `aws-lc-fips-sys` should
upgrade to the most recent release of `aws-lc-fips-sys`.</p>
<p>## Workarounds</p>
<p>In the special cases of using AES-CCM with (M=4, L=2), (M=8, L=2), or
(M=16, L=2), applications can workaround this issue by using AES-CCM
through the EVP AEAD API using implementations
`EVP_aead_aes_128_ccm_bluetooth`, `EVP_aead_aes_128_ccm_bluetooth_8`,
and `EVP_aead_aes_128_ccm_matter` respectively.</p>
<p>Otherwise, there is no workaround and applications using `aws-lc-fips-sys`
should upgrade to the most recent release of `aws-lc-fips-sys`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2026-0043"/>
  </entry>
</feed>
