<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:32:23 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-05841</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05841</link>
      <description>bdu:2023-05841</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05841</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1040 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
Protect. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1040</link>
      <description>certfr-2022-avi-1040</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1040</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-IK84393 — attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take signif…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-ik84393</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: docker-cli-compose, CleanStart: gitea&lt;/p&gt;
&lt;p&gt;CVE-2022-32149 affects multiple packages. An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: docker-cli-compose, CleanStart: gitea&lt;/p&gt;
&lt;p&gt;CVE-2022-32149 affects multiple packages. An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-ik84393</guid>
    </item>
    <item>
      <title>EUVD-2026-239726</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-239726</link>
      <description>EUVD-2026-239726</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-239726</guid>
    </item>
    <item>
      <title>fkie_cve-2022-32149</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-32149</link>
      <description>&lt;p&gt;An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-32149</guid>
    </item>
    <item>
      <title>GHSA-69ch-w2m2-3vjp — golang.org/x/text/language Denial of service via crafted Accept-Language header</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-69ch-w2m2-3vjp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/text&lt;/p&gt;
&lt;p&gt;The BCP 47 tag parser has quadratic time complexity due to inherent aspects of its design. Since the parser is, by design, exposed to untrusted user input, this can be leveraged to force a program to consume significant time parsing Accept-Language headers. The parser cannot be easily rewritten to fix this behavior for various reasons. Instead the solution implemented in this CL is to limit the total complexity of tags passed into ParseAcceptLanguage by limiting the number of dashes in the string to 1000. This should be more than enough for the majority of real world use cases, where the number of tags being sent is likely to be in the single digits.&lt;/p&gt;
&lt;p&gt;### Specific Go Packages Affected
golang.org/x/text/language&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/text&lt;/p&gt;
&lt;p&gt;The BCP 47 tag parser has quadratic time complexity due to inherent aspects of its design. Since the parser is, by design, exposed to untrusted user input, this can be leveraged to force a program to consume significant time parsing Accept-Language headers. The parser cannot be easily rewritten to fix this behavior for various reasons. Instead the solution implemented in this CL is to limit the total complexity of tags passed into ParseAcceptLanguage by limiting the number of dashes in the string to 1000. This should be more than enough for the majority of real world use cases, where the number of tags being sent is likely to be in the single digits.&lt;/p&gt;
&lt;p&gt;### Specific Go Packages Affected
golang.org/x/text/language&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-69ch-w2m2-3vjp</guid>
    </item>
    <item>
      <title>gsd-2022-32149</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-32149</link>
      <description>gsd-2022-32149</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-32149</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-32149 — Denial of service via crafted Accept-Language header in golang.org/x/text/language</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-32149</link>
      <description>msrc_CVE-2022-32149</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-32149</guid>
    </item>
    <item>
      <title>OESA-2024-1527 — podman security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1527</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP2: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.(CVE-2022-32149)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP2: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.(CVE-2022-32149)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1527</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12426-1 — starboard-0.15.11-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12426-1</link>
      <description>&lt;p&gt;starboard-0.15.11-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;starboard-0.15.11-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12426-1</guid>
    </item>
    <item>
      <title>RHBA-2023:4275 — Red Hat Bug Fix Advisory: Red Hat Quay v3.8.11 bug fix release</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2023:4275</link>
      <description>&lt;p&gt;golang: net/http: handle server errors after sending GOAWAY golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags golang: net/url: JoinPath does not strip relative path components in all circumstances golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang: html/template: improper handling of empty HTML attributes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/http: handle server errors after sending GOAWAY golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags golang: net/url: JoinPath does not strip relative path components in all circumstances golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang: html/template: improper handling of empty HTML attributes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2023:4275</guid>
    </item>
    <item>
      <title>SUSE-EL-9-CLIENT-TOOLS-2023-3875 — Security update for SUSE Manager Client Tools</title>
      <link>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2023-3875</link>
      <description>&lt;p&gt;Security update for SUSE Manager Client Tools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Client Tools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2023-3875</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-32149</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-32149</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: golang-x-text, Ubuntu:18.04:LTS: golang-x-text, Ubuntu:20.04:LTS: golang-golang-x-text, Ubuntu:20.04:LTS: golang-x-text, Ubuntu:22.04:LTS: golang-golang-x-text&lt;/p&gt;
&lt;p&gt;An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: golang-x-text, Ubuntu:18.04:LTS: golang-x-text, Ubuntu:20.04:LTS: golang-golang-x-text, Ubuntu:20.04:LTS: golang-x-text, Ubuntu:22.04:LTS: golang-golang-x-text&lt;/p&gt;
&lt;p&gt;An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-32149</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2134 — IBM Spectrum Protect: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2134</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes and Red Hat OpenShift ausnutzen, um einen Cross site Scripting Angriff durchzuführen, Informationen offenzulegen oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes and Red Hat OpenShift ausnutzen, um einen Cross site Scripting Angriff durchzuführen, Informationen offenzulegen oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2134</guid>
    </item>
  </channel>
</rss>
