<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:24:29 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:6346 — Moderate: toolbox security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:6346</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: toolbox, AlmaLinux:9: toolbox-tests&lt;/p&gt;
&lt;p&gt;Toolbox is a tool for Linux operating systems, which allows the use of containerized command line environments. It is built on top of Podman and other standard container technologies from OCI.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)
* golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)
* net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)
* golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)
* golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534)
* golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536)
* golang: html/template: backticks not treated as string delimiters (CVE-2023-24538)
* golang: html/template: improper sanitization of CSS values (CVE-2023-24539)
* golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400)
* golang: net/http: insufficient sanitization of Host header (CVE-2023-29406)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References se…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: toolbox, AlmaLinux:9: toolbox-tests&lt;/p&gt;
&lt;p&gt;Toolbox is a tool for Linux operating systems, which allows the use of containerized command line environments. It is built on top of Podman and other standard container technologies from OCI.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)
* golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)
* net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)
* golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)
* golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534)
* golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536)
* golang: html/template: backticks not treated as string delimiters (CVE-2023-24538)
* golang: html/template: improper sanitization of CSS values (CVE-2023-24539)
* golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400)
* golang: net/http: insufficient sanitization of Host header (CVE-2023-29406)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References se…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:6346</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-KI12594 — Security fixes in cluster-proportional-autoscaler 1.7.1-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ki12594</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cluster-proportional-autoscaler&lt;/p&gt;
&lt;p&gt;Package cluster-proportional-autoscaler version 1.7.1-r0 fixes 7 vulnerabilities: CVE-2021-3121, CVE-2022-3064, CVE-2020-8559, CVE-2019-11254, CVE-2019-11250...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cluster-proportional-autoscaler&lt;/p&gt;
&lt;p&gt;Package cluster-proportional-autoscaler version 1.7.1-r0 fixes 7 vulnerabilities: CVE-2021-3121, CVE-2022-3064, CVE-2020-8559, CVE-2019-11254, CVE-2019-11250...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ki12594</guid>
    </item>
    <item>
      <title>EUVD-2026-229054</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-229054</link>
      <description>EUVD-2026-229054</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-229054</guid>
    </item>
    <item>
      <title>fkie_cve-2022-3064</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-3064</link>
      <description>&lt;p&gt;Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-3064</guid>
    </item>
    <item>
      <title>GHSA-6q6q-88xp-6f2r — yaml package for Go can consume excessive amounts of CPU or memory</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6q6q-88xp-6f2r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gopkg.in/yaml.v2&lt;/p&gt;
&lt;p&gt;Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gopkg.in/yaml.v2&lt;/p&gt;
&lt;p&gt;Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6q6q-88xp-6f2r</guid>
    </item>
    <item>
      <title>gsd-2022-3064</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-3064</link>
      <description>gsd-2022-3064</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-3064</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-3064 — Excessive resource consumption in gopkg.in/yaml.v2</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-3064</link>
      <description>msrc_CVE-2022-3064</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-3064</guid>
    </item>
    <item>
      <title>OESA-2025-1168 — etcd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1168</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: etcd&lt;/p&gt;
&lt;p&gt;%{expand:&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.(CVE-2021-28235)&lt;/p&gt;
&lt;p&gt;Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.(CVE-2022-3064)&lt;/p&gt;
&lt;p&gt;Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor&amp;amp;apos;s position is that this is not a vulnerability.(CVE-2022-34038)&lt;/p&gt;
&lt;p&gt;A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.(CVE-2022-41723)&lt;/p&gt;
&lt;p&gt;etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn&amp;amp;apos;t have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.(CVE-2023-32082)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: etcd&lt;/p&gt;
&lt;p&gt;%{expand:&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.(CVE-2021-28235)&lt;/p&gt;
&lt;p&gt;Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.(CVE-2022-3064)&lt;/p&gt;
&lt;p&gt;Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor&amp;amp;apos;s position is that this is not a vulnerability.(CVE-2022-34038)&lt;/p&gt;
&lt;p&gt;A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.(CVE-2022-41723)&lt;/p&gt;
&lt;p&gt;etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn&amp;amp;apos;t have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.(CVE-2023-32082)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1168</guid>
    </item>
    <item>
      <title>RHSA-2023:0698 — Red Hat Security Advisory: OpenShift Container Platform 4.10.52 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:0698</link>
      <description>&lt;p&gt;go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:0698</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-3064</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-3064</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: golang-yaml.v2, Ubuntu:Pro:18.04:LTS: golang-yaml.v2, Ubuntu:Pro:18.04:LTS: singularity-container, Ubuntu:18.04:LTS: webhook, Ubuntu:20.04:LTS: golang-yaml.v2, Ubuntu:20.04:LTS: golang-github-coreos-discovery-etcd-io, Ubuntu:20.04:LTS: webhook, Ubuntu:22.04:LTS: golang-github-coreos-discovery-etcd-io, Ubuntu:22.04:LTS: webhook, Ubuntu:24.04:LTS: golang-github-coreos-discovery-etcd-io and 8 more&lt;/p&gt;
&lt;p&gt;Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: golang-yaml.v2, Ubuntu:Pro:18.04:LTS: golang-yaml.v2, Ubuntu:Pro:18.04:LTS: singularity-container, Ubuntu:18.04:LTS: webhook, Ubuntu:20.04:LTS: golang-yaml.v2, Ubuntu:20.04:LTS: golang-github-coreos-discovery-etcd-io, Ubuntu:20.04:LTS: webhook, Ubuntu:22.04:LTS: golang-github-coreos-discovery-etcd-io, Ubuntu:22.04:LTS: webhook, Ubuntu:24.04:LTS: golang-github-coreos-discovery-etcd-io and 8 more&lt;/p&gt;
&lt;p&gt;Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-3064</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0468 — Red Hat OpenShift: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0468</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0468</guid>
    </item>
  </channel>
</rss>
