<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:41:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-233523</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-233523</link>
      <description>EUVD-2026-233523</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-233523</guid>
    </item>
    <item>
      <title>fkie_cve-2022-39278</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39278</link>
      <description>&lt;p&gt;Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted or oversized message which results in the control plane crashing when the Kubernetes validating or mutating webhook service is exposed publicly. This endpoint is served over TLS port 15017, but does not require any authentication from the attacker. For simple installations, Istiod is typically only reachable from within the cluster, limiting the blast radius. However, for some deployments, especially external istiod topologies, this port is exposed over the public internet. Versions 1.15.2, 1.14.5, and 1.13.9 contain patches for this issue. There are no effective workarounds, beyond upgrading. This bug is due to an error in `regexp.Compile` in Go.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted or oversized message which results in the control plane crashing when the Kubernetes validating or mutating webhook service is exposed publicly. This endpoint is served over TLS port 15017, but does not require any authentication from the attacker. For simple installations, Istiod is typically only reachable from within the cluster, limiting the blast radius. However, for some deployments, especially external istiod topologies, this port is exposed over the public internet. Versions 1.15.2, 1.14.5, and 1.13.9 contain patches for this issue. There are no effective workarounds, beyond upgrading. This bug is due to an error in `regexp.Compile` in Go.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-39278</guid>
    </item>
    <item>
      <title>gsd-2022-39278</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-39278</link>
      <description>gsd-2022-39278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-39278</guid>
    </item>
    <item>
      <title>RHSA-2023:0542 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.3.1 Containers security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:0542</link>
      <description>&lt;p&gt;goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters kiali: error message spoofing in kiali UI golang: net/http: handle server errors after sending GOAWAY golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service Istio: Denial of service attack via a specially crafted message golang: regexp/syntax: limit memory used by parsing regexps&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters kiali: error message spoofing in kiali UI golang: net/http: handle server errors after sending GOAWAY golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service Istio: Denial of service attack via a specially crafted message golang: regexp/syntax: limit memory used by parsing regexps&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:0542</guid>
    </item>
  </channel>
</rss>
