<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:18:32 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CN84623 — Within HostnameError</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cn84623</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opentofu-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the opentofu-fips package. Within HostnameError. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opentofu-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the opentofu-fips package. Within HostnameError. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cn84623</guid>
    </item>
    <item>
      <title>EUVD-2026-38736</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-38736</link>
      <description>EUVD-2026-38736</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-38736</guid>
    </item>
    <item>
      <title>fkie_cve-2020-8912</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8912</link>
      <description>&lt;p&gt;A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-CTR. Using this in combination with a decryption oracle can reveal the authentication key used by AES-GCM as decrypting the GMAC tag leaves the authentication key recoverable as an algebraic equation. It is recommended to update your SDK to V2 or later, and re-encrypt your files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-CTR. Using this in combination with a decryption oracle can reveal the authentication key used by AES-GCM as decrypting the GMAC tag leaves the authentication key recoverable as an algebraic equation. It is recommended to update your SDK to V2 or later, and re-encrypt your files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-8912</guid>
    </item>
    <item>
      <title>GHSA-7f33-f4f5-xwgw — In-band key negotiation issue in AWS S3 Crypto SDK for golang</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7f33-f4f5-xwgw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/aws/aws-sdk-go&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The golang AWS S3 Crypto SDK is impacted by an issue that can result in loss of confidentiality and message forgery. The attack requires write access to the bucket in question, and that the attacker has access to an endpoint that reveals decryption failures (without revealing the plaintext) and that when encrypting the GCM option was chosen as content cipher.&lt;/p&gt;
&lt;p&gt;### Risk/Severity&lt;/p&gt;
&lt;p&gt;The vulnerability pose insider risks/privilege escalation risks, circumventing KMS controls for stored data.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This advisory describes the plaintext revealing vulnerabilities in the golang AWS S3 Crypto SDK, with a similar issue in the non &amp;#34;strict&amp;#34; versions of C++ and Java S3 Crypto SDKs being present as well.&lt;/p&gt;
&lt;p&gt;V1 prior to 1.34.0 of the S3 crypto SDK does not authenticate the algorithm parameters for the data encryption key.&lt;/p&gt;
&lt;p&gt;An attacker with write access to the bucket can use this in order to change the encryption algorithm of an object in the bucket, which can lead to problems depending on the supported algorithms. For example, a switch from AES-GCM to AES-CTR in combination with a decryption oracle can reveal the authentication key used by AES-GCM as decrypting the GMAC tag leaves the authentication key recoverable as an algebraic equation.&lt;/p&gt;
&lt;p&gt;By default, the only available algorithms in the SDK are AES-GCM and AES-CBC. Switching the algorithm from AES-GCM to AES-CBC can be used as way to reconstruct the plaintext through an oracle endpoint revealing decryption failures, by b…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/aws/aws-sdk-go&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The golang AWS S3 Crypto SDK is impacted by an issue that can result in loss of confidentiality and message forgery. The attack requires write access to the bucket in question, and that the attacker has access to an endpoint that reveals decryption failures (without revealing the plaintext) and that when encrypting the GCM option was chosen as content cipher.&lt;/p&gt;
&lt;p&gt;### Risk/Severity&lt;/p&gt;
&lt;p&gt;The vulnerability pose insider risks/privilege escalation risks, circumventing KMS controls for stored data.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This advisory describes the plaintext revealing vulnerabilities in the golang AWS S3 Crypto SDK, with a similar issue in the non &amp;#34;strict&amp;#34; versions of C++ and Java S3 Crypto SDKs being present as well.&lt;/p&gt;
&lt;p&gt;V1 prior to 1.34.0 of the S3 crypto SDK does not authenticate the algorithm parameters for the data encryption key.&lt;/p&gt;
&lt;p&gt;An attacker with write access to the bucket can use this in order to change the encryption algorithm of an object in the bucket, which can lead to problems depending on the supported algorithms. For example, a switch from AES-GCM to AES-CTR in combination with a decryption oracle can reveal the authentication key used by AES-GCM as decrypting the GMAC tag leaves the authentication key recoverable as an algebraic equation.&lt;/p&gt;
&lt;p&gt;By default, the only available algorithms in the SDK are AES-GCM and AES-CBC. Switching the algorithm from AES-GCM to AES-CBC can be used as way to reconstruct the plaintext through an oracle endpoint revealing decryption failures, by b…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7f33-f4f5-xwgw</guid>
    </item>
    <item>
      <title>gsd-2020-8912</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-8912</link>
      <description>gsd-2020-8912</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-8912</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14599-1 — govulncheck-vulndb-0.0.20241213T205935-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14599-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20241213T205935-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20241213T205935-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14599-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3851 — Red Hat Security Advisory: Red Hat 3scale API Management 2.11.0 Release - Container Images</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3851</link>
      <description>&lt;p&gt;aws/aws-sdk-go: CBC padding oracle issue in AWS S3 Crypto SDK for golang aws-sdk-go: In-band key negotiation issue in AWS S3 Crypto SDK for golang RHOAM: XSS in 3scale at various places 3scale: missing validation of access token nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;aws/aws-sdk-go: CBC padding oracle issue in AWS S3 Crypto SDK for golang aws-sdk-go: In-band key negotiation issue in AWS S3 Crypto SDK for golang RHOAM: XSS in 3scale at various places 3scale: missing validation of access token nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3851</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0794 — Dell ECS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794</guid>
    </item>
  </channel>
</rss>
