<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:42:51 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-01889</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-01889</link>
      <description>bdu:2020-01889</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-01889</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2018-16875 — CVE-2018-16875 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2018-16875</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2018-16875</guid>
    </item>
    <item>
      <title>EUVD-2026-68416</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-68416</link>
      <description>EUVD-2026-68416</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-68416</guid>
    </item>
    <item>
      <title>fkie_cve-2018-16875</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-16875</link>
      <description>&lt;p&gt;The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-16875</guid>
    </item>
    <item>
      <title>GHSA-8gx8-4ch8-vgp8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8gx8-4ch8-vgp8</link>
      <description>&lt;p&gt;The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8gx8-4ch8-vgp8</guid>
    </item>
    <item>
      <title>gsd-2018-16875</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-16875</link>
      <description>gsd-2018-16875</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-16875</guid>
    </item>
    <item>
      <title>msrc_CVE-2018-16875 — The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for ea…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2018-16875</link>
      <description>msrc_CVE-2018-16875</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2018-16875</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:0189-1 — Security update for docker</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:0189-1</link>
      <description>&lt;p&gt;Security update for docker&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for docker&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:0189-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2023-0052 — webpki: CPU denial of service in certificate path building</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2023-0052</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: webpki&lt;/p&gt;
&lt;p&gt;When this crate is given a pathological certificate chain to validate, it will
spend CPU time exponential with the number of candidate certificates at each
step of path building.&lt;/p&gt;
&lt;p&gt;Both TLS clients and TLS servers that accept client certificate are affected.&lt;/p&gt;
&lt;p&gt;This was previously reported in
&amp;lt;https://github.com/briansmith/webpki/issues/69&amp;gt; and re-reported recently
by Luke Malinowski.&lt;/p&gt;
&lt;p&gt;webpki 0.22.1 included a partial fix and webpki 0.22.2 added further fixes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: webpki&lt;/p&gt;
&lt;p&gt;When this crate is given a pathological certificate chain to validate, it will
spend CPU time exponential with the number of candidate certificates at each
step of path building.&lt;/p&gt;
&lt;p&gt;Both TLS clients and TLS servers that accept client certificate are affected.&lt;/p&gt;
&lt;p&gt;This was previously reported in
&amp;lt;https://github.com/briansmith/webpki/issues/69&amp;gt; and re-reported recently
by Luke Malinowski.&lt;/p&gt;
&lt;p&gt;webpki 0.22.1 included a partial fix and webpki 0.22.2 added further fixes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2023-0052</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:4297-1 — Security update for containerd, docker and go</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:4297-1</link>
      <description>&lt;p&gt;Security update for containerd, docker and go&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for containerd, docker and go&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:4297-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-16875</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-16875</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:18.04:LTS: golang-1.8, Ubuntu:18.04:LTS: golang-1.9&lt;/p&gt;
&lt;p&gt;The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:18.04:LTS: golang-1.8, Ubuntu:18.04:LTS: golang-1.9&lt;/p&gt;
&lt;p&gt;The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-16875</guid>
    </item>
  </channel>
</rss>
