<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:24:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03823</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03823</link>
      <description>bdu:2023-03823</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03823</guid>
    </item>
    <item>
      <title>certfr-2022-avi-363 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-363</link>
      <description>certfr-2022-avi-363</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-363</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-JU62349 — Security fixes for CVE-2018-10237, CVE-2020-8908, CVE-2021-22569, CVE-2021-22570, CVE-2022-3171, CVE-2022-3509, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ju62349</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-hive package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-hive package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ju62349</guid>
    </item>
    <item>
      <title>EUVD-2026-232104</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232104</link>
      <description>EUVD-2026-232104</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232104</guid>
    </item>
    <item>
      <title>fkie_cve-2021-22569</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22569</link>
      <description>&lt;p&gt;An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-22569</guid>
    </item>
    <item>
      <title>GHSA-wrvw-hg22-4m67 — A potential Denial of Service issue in protobuf-java</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wrvw-hg22-4m67</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.google.protobuf:protobuf-java, RubyGems: google-protobuf, Maven: com.google.protobuf:protobuf-kotlin&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A potential Denial of Service issue in protobuf-java was discovered in the parsing procedure for binary data.&lt;/p&gt;
&lt;p&gt;Reporter: [OSS-Fuzz](https://github.com/google/oss-fuzz)&lt;/p&gt;
&lt;p&gt;Affected versions: All versions of Java Protobufs (including Kotlin and JRuby) prior to the versions listed below. Protobuf &amp;#34;javalite&amp;#34; users (typically Android) are not affected.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;[CVE-2021-22569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22569) **High** - CVSS Score: 7.5,  An implementation weakness in how unknown fields are parsed in Java. A small (~800 KB) malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated GC pauses.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;For reproduction details, please refer to the oss-fuzz issue that identifies the specific inputs that exercise this parsing weakness.&lt;/p&gt;
&lt;p&gt;## Remediation and Mitigation&lt;/p&gt;
&lt;p&gt;Please update to the latest available versions of the following packages:&lt;/p&gt;
&lt;p&gt;- protobuf-java (3.16.1, 3.18.2, 3.19.2) 
- protobuf-kotlin (3.18.2, 3.19.2)
- google-protobuf [JRuby  gem only] (3.19.2)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.google.protobuf:protobuf-java, RubyGems: google-protobuf, Maven: com.google.protobuf:protobuf-kotlin&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A potential Denial of Service issue in protobuf-java was discovered in the parsing procedure for binary data.&lt;/p&gt;
&lt;p&gt;Reporter: [OSS-Fuzz](https://github.com/google/oss-fuzz)&lt;/p&gt;
&lt;p&gt;Affected versions: All versions of Java Protobufs (including Kotlin and JRuby) prior to the versions listed below. Protobuf &amp;#34;javalite&amp;#34; users (typically Android) are not affected.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;[CVE-2021-22569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22569) **High** - CVSS Score: 7.5,  An implementation weakness in how unknown fields are parsed in Java. A small (~800 KB) malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated GC pauses.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;For reproduction details, please refer to the oss-fuzz issue that identifies the specific inputs that exercise this parsing weakness.&lt;/p&gt;
&lt;p&gt;## Remediation and Mitigation&lt;/p&gt;
&lt;p&gt;Please update to the latest available versions of the following packages:&lt;/p&gt;
&lt;p&gt;- protobuf-java (3.16.1, 3.18.2, 3.19.2) 
- protobuf-kotlin (3.18.2, 3.19.2)
- google-protobuf [JRuby  gem only] (3.19.2)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wrvw-hg22-4m67</guid>
    </item>
    <item>
      <title>gsd-2021-22569</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-22569</link>
      <description>gsd-2021-22569</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-22569</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-22569 — Denial of Service of protobuf-java parsing procedure</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-22569</link>
      <description>msrc_CVE-2021-22569</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-22569</guid>
    </item>
    <item>
      <title>OESA-2022-1694 — protobuf security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1694</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: protobuf&lt;/p&gt;
&lt;p&gt;Protocol Buffers (a.k.a., protobuf) are Google&amp;amp;apos;s language-neutral, platform-neutral, extensible mechanism for serializing structured data. You can find protobuf&amp;amp;apos;s documentation on the Google Developers site.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.(CVE-2021-22569)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: protobuf&lt;/p&gt;
&lt;p&gt;Protocol Buffers (a.k.a., protobuf) are Google&amp;amp;apos;s language-neutral, platform-neutral, extensible mechanism for serializing structured data. You can find protobuf&amp;amp;apos;s documentation on the Google Developers site.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.(CVE-2021-22569)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1694</guid>
    </item>
    <item>
      <title>RHSA-2022:1013 — Red Hat Security Advisory: Red Hat Integration Camel Extensions for Quarkus 2.2.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1013</link>
      <description>&lt;p&gt;guava: local information disclosure via temporary directory created with unsafe permissions bouncycastle: Timing issue within the EC math library mysql-connector-java: unauthorized access to critical kubernetes-client: Insecure deserialization in unmarshalYaml method protobuf-java: potential DoS in the parsing procedure for binary data maven: Block repositories using http by default jersey: Local information disclosure via system temporary directory jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way xml-security: XPath Transform abuse allows for information disclosure cron-utils: template Injection leading to unauthenticated Remote Code Execution h2: Remote Code Execution in Console&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;guava: local information disclosure via temporary directory created with unsafe permissions bouncycastle: Timing issue within the EC math library mysql-connector-java: unauthorized access to critical kubernetes-client: Insecure deserialization in unmarshalYaml method protobuf-java: potential DoS in the parsing procedure for binary data maven: Block repositories using http by default jersey: Local information disclosure via system temporary directory jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way xml-security: XPath Transform abuse allows for information disclosure cron-utils: template Injection leading to unauthenticated Remote Code Execution h2: Remote Code Execution in Console&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1013</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:2783-2 — Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcry…</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:2783-2</link>
      <description>&lt;p&gt;Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:2783-2</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-22569</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22569</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: protobuf, Ubuntu:Pro:16.04:LTS: protobuf, Ubuntu:18.04:LTS: protobuf, Ubuntu:20.04:LTS: protobuf, Ubuntu:22.04:LTS: protobuf&lt;/p&gt;
&lt;p&gt;An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: protobuf, Ubuntu:Pro:16.04:LTS: protobuf, Ubuntu:18.04:LTS: protobuf, Ubuntu:20.04:LTS: protobuf, Ubuntu:22.04:LTS: protobuf&lt;/p&gt;
&lt;p&gt;An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22569</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</guid>
    </item>
  </channel>
</rss>
