<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:14:49 +0000</lastBuildDate>
    <item>
      <title>certfr-2023-avi-0272 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0272</link>
      <description>certfr-2023-avi-0272</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0272</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-PT09141 — Security fix for CVE-2022-41721 applied in: wavefront-collector-for-kubernetes 1.13.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-pt09141</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: wavefront-collector-for-kubernetes&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the wavefront-collector-for-kubernetes package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: wavefront-collector-for-kubernetes&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the wavefront-collector-for-kubernetes package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-pt09141</guid>
    </item>
    <item>
      <title>EUVD-2026-227110</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-227110</link>
      <description>EUVD-2026-227110</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-227110</guid>
    </item>
    <item>
      <title>fkie_cve-2022-41721</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41721</link>
      <description>&lt;p&gt;A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-41721</guid>
    </item>
    <item>
      <title>GHSA-fxg5-wq6x-vr4w — golang.org/x/net/http2/h2c vulnerable to request smuggling attack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fxg5-wq6x-vr4w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/net&lt;/p&gt;
&lt;p&gt;A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.&lt;/p&gt;
&lt;p&gt;### Specific Go Packages Affected
golang.org/x/net/http2/h2c&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/net&lt;/p&gt;
&lt;p&gt;A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.&lt;/p&gt;
&lt;p&gt;### Specific Go Packages Affected
golang.org/x/net/http2/h2c&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fxg5-wq6x-vr4w</guid>
    </item>
    <item>
      <title>gsd-2022-41721</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-41721</link>
      <description>gsd-2022-41721</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-41721</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-41721 — Request smuggling due to improper request handling in golang.org/x/net/http2/h2c</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-41721</link>
      <description>msrc_CVE-2022-41721</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-41721</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12666-1 — caddy-2.6.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12666-1</link>
      <description>&lt;p&gt;caddy-2.6.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;caddy-2.6.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12666-1</guid>
    </item>
    <item>
      <title>RHSA-2023:1326 — Red Hat Security Advisory: OpenShift Container Platform 4.13.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1326</link>
      <description>&lt;p&gt;go-yaml: Denial of Service in go-yaml goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be mongo-go-driver: specific cstrings input may not be properly validated golang: out-of-bounds read in golang.org/x/text/language leads to DoS prometheus/client_golang: Denial of service using InstrumentHandlerCounter helm: Denial of service through through repository index file helm: Denial of service through schema file golang: crash in a golang.org/x/crypto/ssh server vault: insufficient certificate revocation list checking golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests x/net/http2/h2c: request smuggling golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption exporter-toolkit: authentication bypass via cache poisoning vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File hashicorp/vault: Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata hashicorp/vault: Cache-Timing Attacks During Seal and Unseal Operations helm: getHostByName Function Information Disclosure containerd: Supplementary groups are not set up properly runc: Rootless runc makes `/sys/fs/cgroup` writable runc: volume mount race condition (regression of CVE-2019-19921) runc: AppArmor can be bypassed when `/pro…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go-yaml: Denial of Service in go-yaml goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be mongo-go-driver: specific cstrings input may not be properly validated golang: out-of-bounds read in golang.org/x/text/language leads to DoS prometheus/client_golang: Denial of service using InstrumentHandlerCounter helm: Denial of service through through repository index file helm: Denial of service through schema file golang: crash in a golang.org/x/crypto/ssh server vault: insufficient certificate revocation list checking golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests x/net/http2/h2c: request smuggling golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption exporter-toolkit: authentication bypass via cache poisoning vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File hashicorp/vault: Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata hashicorp/vault: Cache-Timing Attacks During Seal and Unseal Operations helm: getHostByName Function Information Disclosure containerd: Supplementary groups are not set up properly runc: Rootless runc makes `/sys/fs/cgroup` writable runc: volume mount race condition (regression of CVE-2019-19921) runc: AppArmor can be bypassed when `/pro…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1326</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0794 — Dell ECS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794</guid>
    </item>
  </channel>
</rss>
