<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:33:14 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-591 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-591</link>
      <description>certfr-2022-avi-591</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-591</guid>
    </item>
    <item>
      <title>EUVD-2026-54669</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-54669</link>
      <description>EUVD-2026-54669</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-54669</guid>
    </item>
    <item>
      <title>fkie_cve-2019-11840</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-11840</link>
      <description>&lt;p&gt;An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-11840</guid>
    </item>
    <item>
      <title>GHSA-r5c5-pr8j-pfp7 — golang.org/x/crypto/salsa20/salsa uses insufficiently random values</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r5c5-pr8j-pfp7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/crypto&lt;/p&gt;
&lt;p&gt;An issue was discovered in supplementary Go cryptography libraries, aka golang-googlecode-go-crypto, before 2019-03-20. A flaw was found in the amd64 implementation of golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.&lt;/p&gt;
&lt;p&gt;### Specific Go Packages Affected
golang.org/x/crypto/salsa20/salsa&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/crypto&lt;/p&gt;
&lt;p&gt;An issue was discovered in supplementary Go cryptography libraries, aka golang-googlecode-go-crypto, before 2019-03-20. A flaw was found in the amd64 implementation of golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.&lt;/p&gt;
&lt;p&gt;### Specific Go Packages Affected
golang.org/x/crypto/salsa20/salsa&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r5c5-pr8j-pfp7</guid>
    </item>
    <item>
      <title>gsd-2019-11840</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-11840</link>
      <description>gsd-2019-11840</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-11840</guid>
    </item>
    <item>
      <title>RHBA-2020:0062 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.3 image release advisory</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2020:0062</link>
      <description>&lt;p&gt;golang.org/x/crypto: Keystream loop in amd64 assembly when overflowing 32-bit counter golang: HTTP/1.1 headers with a space before the colon leads to filter bypass or request smuggling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang.org/x/crypto: Keystream loop in amd64 assembly when overflowing 32-bit counter golang: HTTP/1.1 headers with a space before the colon leads to filter bypass or request smuggling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2020:0062</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-11840</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-11840</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: golang-go.crypto, Ubuntu:Pro:16.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: golang-go.crypto, Ubuntu:Pro:20.04:LTS: snapd, Ubuntu:22.04:LTS: snapd, Ubuntu:24.04:LTS: snapd, Ubuntu:25.10: snapd, Ubuntu:26.04:LTS: snapd&lt;/p&gt;
&lt;p&gt;An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: golang-go.crypto, Ubuntu:Pro:16.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: golang-go.crypto, Ubuntu:Pro:20.04:LTS: snapd, Ubuntu:22.04:LTS: snapd, Ubuntu:24.04:LTS: snapd, Ubuntu:25.10: snapd, Ubuntu:26.04:LTS: snapd&lt;/p&gt;
&lt;p&gt;An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-11840</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0496 — Red Hat OpenShift: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0496</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Informationen offenzulegen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Informationen offenzulegen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0496</guid>
    </item>
  </channel>
</rss>
