<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:56:43 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:6712 — Moderate: python-wheel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:6712</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-wheel, AlmaLinux:9: python3-wheel-wheel&lt;/p&gt;
&lt;p&gt;Wheel is the reference implementation of the Python wheel packaging standard, as defined in PEP 427.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli (CVE-2022-40898)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-wheel, AlmaLinux:9: python3-wheel-wheel&lt;/p&gt;
&lt;p&gt;Wheel is the reference implementation of the Python wheel packaging standard, as defined in PEP 427.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli (CVE-2022-40898)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:6712</guid>
    </item>
    <item>
      <title>bdu:2023-08101</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08101</link>
      <description>bdu:2023-08101</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08101</guid>
    </item>
    <item>
      <title>BREW-bzt-CVE-2022-40898 — pypa/wheel vulnerable to Regular Expression denial of service (ReDoS)</title>
      <link>https://cve.radiocsirt.org/vuln/brew-bzt-cve-2022-40898</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: bzt&lt;/p&gt;
&lt;p&gt;Python Packaging Authority (PyPA) Wheel is a reference implementation of the Python wheel packaging standard. Wheel 0.37.1 and earlier are vulnerable to a Regular Expression denial of service via attacker controlled input to the wheel cli. The vulnerable regex is used to verify the validity of Wheel file names. This has been patched in version 0.38.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: bzt&lt;/p&gt;
&lt;p&gt;Python Packaging Authority (PyPA) Wheel is a reference implementation of the Python wheel packaging standard. Wheel 0.37.1 and earlier are vulnerable to a Regular Expression denial of service via attacker controlled input to the wheel cli. The vulnerable regex is used to verify the validity of Wheel file names. This has been patched in version 0.38.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-bzt-cve-2022-40898</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0272 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0272</link>
      <description>certfr-2023-avi-0272</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0272</guid>
    </item>
    <item>
      <title>EUVD-2026-230114</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-230114</link>
      <description>EUVD-2026-230114</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-230114</guid>
    </item>
    <item>
      <title>fkie_cve-2022-40898</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-40898</link>
      <description>&lt;p&gt;An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-40898</guid>
    </item>
    <item>
      <title>GHSA-qwmp-2cf2-g9g6 — pypa/wheel vulnerable to Regular Expression denial of service (ReDoS)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qwmp-2cf2-g9g6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: wheel&lt;/p&gt;
&lt;p&gt;Python Packaging Authority (PyPA) Wheel is a reference implementation of the Python wheel packaging standard. Wheel 0.37.1 and earlier are vulnerable to a Regular Expression denial of service via attacker controlled input to the wheel cli. The vulnerable regex is used to verify the validity of Wheel file names. This has been patched in version 0.38.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: wheel&lt;/p&gt;
&lt;p&gt;Python Packaging Authority (PyPA) Wheel is a reference implementation of the Python wheel packaging standard. Wheel 0.37.1 and earlier are vulnerable to a Regular Expression denial of service via attacker controlled input to the wheel cli. The vulnerable regex is used to verify the validity of Wheel file names. This has been patched in version 0.38.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qwmp-2cf2-g9g6</guid>
    </item>
    <item>
      <title>gsd-2022-40898</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-40898</link>
      <description>gsd-2022-40898</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-40898</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-40898 — An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a de…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-40898</link>
      <description>msrc_CVE-2022-40898</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-40898</guid>
    </item>
    <item>
      <title>OESA-2023-1904 — python-wheel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1904</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-wheel, openEuler:20.03-LTS-SP3: python-wheel, openEuler:22.03-LTS: python-wheel, openEuler:22.03-LTS-SP1: python-wheel, openEuler:22.03-LTS-SP2: python-wheel&lt;/p&gt;
&lt;p&gt;A built-package format for Python. A wheel is a ZIP-format archive with a specially formatted filename and the .whl extension. It is designed to contain all the files for a PEP 376 compatible install in a way that is very close to the on-disk format.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.(CVE-2022-40898)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-wheel, openEuler:20.03-LTS-SP3: python-wheel, openEuler:22.03-LTS: python-wheel, openEuler:22.03-LTS-SP1: python-wheel, openEuler:22.03-LTS-SP2: python-wheel&lt;/p&gt;
&lt;p&gt;A built-package format for Python. A wheel is a ZIP-format archive with a specially formatted filename and the .whl extension. It is designed to contain all the files for a PEP 376 compatible install in a way that is very close to the on-disk format.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.(CVE-2022-40898)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1904</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12645-1 — python310-ciscoconfparse-1.7.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12645-1</link>
      <description>&lt;p&gt;python310-ciscoconfparse-1.7.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-ciscoconfparse-1.7.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12645-1</guid>
    </item>
    <item>
      <title>PYSEC-2022-43017</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2022-43017</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: wheel&lt;/p&gt;
&lt;p&gt;An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: wheel&lt;/p&gt;
&lt;p&gt;An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2022-43017</guid>
    </item>
    <item>
      <title>RHSA-2023:6793 — Red Hat Security Advisory: rh-python38-python security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:6793</link>
      <description>&lt;p&gt;python: tarfile module directory traversal pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli python: CPU denial of service via inefficient IDNA decoder python-cryptography: memory corruption via immutable objects python: urllib.parse url blocklisting bypass python-requests: Unintended leak of Proxy-Authorization header python: TLS handshake bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: tarfile module directory traversal pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli python: CPU denial of service via inefficient IDNA decoder python-cryptography: memory corruption via immutable objects python: urllib.parse url blocklisting bypass python-requests: Unintended leak of Proxy-Authorization header python: TLS handshake bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:6793</guid>
    </item>
    <item>
      <title>RLSA-2023:6712 — Moderate: python-wheel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2023:6712</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: python-wheel&lt;/p&gt;
&lt;p&gt;Wheel is the reference implementation of the Python wheel packaging standard, as defined in PEP 427.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli (CVE-2022-40898)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux 9.3 Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: python-wheel&lt;/p&gt;
&lt;p&gt;Wheel is the reference implementation of the Python wheel packaging standard, as defined in PEP 427.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli (CVE-2022-40898)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux 9.3 Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2023:6712</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:0088-2 — Security update for python-wheel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:0088-2</link>
      <description>&lt;p&gt;Security update for python-wheel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-wheel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:0088-2</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-40898</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-40898</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:14.04:LTS: wheel, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:16.04:LTS: wheel, Ubuntu:18.04:LTS: python-pip, Ubuntu:18.04:LTS: wheel, Ubuntu:20.04:LTS: python-pip, Ubuntu:20.04:LTS: wheel, Ubuntu:22.04:LTS: python-pip, Ubuntu:22.04:LTS: wheel&lt;/p&gt;
&lt;p&gt;An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:14.04:LTS: wheel, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:16.04:LTS: wheel, Ubuntu:18.04:LTS: python-pip, Ubuntu:18.04:LTS: wheel, Ubuntu:20.04:LTS: python-pip, Ubuntu:20.04:LTS: wheel, Ubuntu:22.04:LTS: python-pip, Ubuntu:22.04:LTS: wheel&lt;/p&gt;
&lt;p&gt;An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-40898</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1424 — Xerox FreeFlow Print Server für Solaris: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1424</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1424</guid>
    </item>
  </channel>
</rss>
