<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:32:34 +0000</lastBuildDate>
    <item>
      <title>ALSA-2019:2925 — Important: nodejs:10 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:2925</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (10.16.3).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using PRIORITY frames results in excessive resource consumption (CVE-2019-9513)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515)&lt;/p&gt;
&lt;p&gt;* HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516)&lt;/p&gt;
&lt;p&gt;* HTTP/2: request for large response leads to denial of service (CVE-2019-9517)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using empty frames results in excessive resource consumption (CVE-2019-9518)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (10.16.3).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using PRIORITY frames results in excessive resource consumption (CVE-2019-9513)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515)&lt;/p&gt;
&lt;p&gt;* HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516)&lt;/p&gt;
&lt;p&gt;* HTTP/2: request for large response leads to denial of service (CVE-2019-9517)&lt;/p&gt;
&lt;p&gt;* HTTP/2: flood using empty frames results in excessive resource consumption (CVE-2019-9518)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:2925</guid>
    </item>
    <item>
      <title>bdu:2019-02995</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-02995</link>
      <description>bdu:2019-02995</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-02995</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2019-9514 — CVE-2019-9514 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2019-9514</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2019-9514</guid>
    </item>
    <item>
      <title>certfr-2019-avi-388 — De multiples vulnérabilités ont été découvertes dans Apple SwiftNIO.
Elles permettent à un attaquant de provoquer un dé…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-388</link>
      <description>certfr-2019-avi-388</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-388</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-AF65508 — Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-af65508</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: containerd&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the containerd package. Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: containerd&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the containerd package. Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-af65508</guid>
    </item>
    <item>
      <title>EUVD-2026-52957</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-52957</link>
      <description>EUVD-2026-52957</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-52957</guid>
    </item>
    <item>
      <title>fkie_cve-2019-9514</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-9514</link>
      <description>&lt;p&gt;Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-9514</guid>
    </item>
    <item>
      <title>GHSA-39qc-96h7-956f — golang.org/x/net/http vulnerable to a reset flood</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-39qc-96h7-956f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/net&lt;/p&gt;
&lt;p&gt;Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. Servers that accept direct connections from untrusted clients could be remotely made to allocate an unlimited amount of memory, until the program crashes. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.&lt;/p&gt;
&lt;p&gt;### Specific Go Packages Affected
golang.org/x/net/http2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/net&lt;/p&gt;
&lt;p&gt;Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. Servers that accept direct connections from untrusted clients could be remotely made to allocate an unlimited amount of memory, until the program crashes. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.&lt;/p&gt;
&lt;p&gt;### Specific Go Packages Affected
golang.org/x/net/http2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-39qc-96h7-956f</guid>
    </item>
    <item>
      <title>gsd-2019-9514</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-9514</link>
      <description>gsd-2019-9514</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-9514</guid>
    </item>
    <item>
      <title>OESA-2025-1052 — podman security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1052</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.(CVE-2019-9514)&#13;
&#13;
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)&#13;
&#13;
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request&amp;amp;apos;s Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.(CVE-2022-2880)&#13;
&#13;
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.(CVE-2019-9514)&#13;
&#13;
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)&#13;
&#13;
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request&amp;amp;apos;s Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.(CVE-2022-2880)&#13;
&#13;
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1052</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:2000-1 — Security update for go1.12</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:2000-1</link>
      <description>&lt;p&gt;Security update for go1.12&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.12&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:2000-1</guid>
    </item>
    <item>
      <title>RHBA-2019:2819 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.1.17 packages update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2019:2819</link>
      <description>&lt;p&gt;HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2019:2819</guid>
    </item>
    <item>
      <title>RUSTSEC-2024-0003 — Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2024-0003</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: h2&lt;/p&gt;
&lt;p&gt;An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the
generation of reset frames on the victim endpoint.
By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion,
resulting in Out Of Memory (OOM) and high CPU usage.&lt;/p&gt;
&lt;p&gt;This fix is corrected in [hyperium/h2#737](https://github.com/hyperium/h2/pull/737), which limits the total number of
internal error resets emitted by default before the connection is closed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: h2&lt;/p&gt;
&lt;p&gt;An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the
generation of reset frames on the victim endpoint.
By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion,
resulting in Out Of Memory (OOM) and high CPU usage.&lt;/p&gt;
&lt;p&gt;This fix is corrected in [hyperium/h2#737](https://github.com/hyperium/h2/pull/737), which limits the total number of
internal error resets emitted by default before the connection is closed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2024-0003</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:14246-1 — Security update for Mozilla Firefox</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:14246-1</link>
      <description>&lt;p&gt;Security update for Mozilla Firefox&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for Mozilla Firefox&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:14246-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-9514</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-9514</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:Pro:14.04:LTS: nodejs, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:16.04:LTS: golang-google-grpc, Ubuntu:16.04:LTS: grpc, Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:16.04:LTS: trafficserver, Ubuntu:18.04:LTS: twisted, Ubuntu:18.04:LTS: golang-1.10 and 19 more&lt;/p&gt;
&lt;p&gt;Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:Pro:14.04:LTS: nodejs, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:16.04:LTS: golang-google-grpc, Ubuntu:16.04:LTS: grpc, Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:16.04:LTS: trafficserver, Ubuntu:18.04:LTS: twisted, Ubuntu:18.04:LTS: golang-1.10 and 19 more&lt;/p&gt;
&lt;p&gt;Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-9514</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0770 — IBM DB2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</guid>
    </item>
  </channel>
</rss>
