<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:13:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-05611</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05611</link>
      <description>bdu:2023-05611</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05611</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0337 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0337</link>
      <description>certfr-2023-avi-0337</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0337</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-GH89210 — Security fixes for CVE-2015-0886, CVE-2020-8908, CVE-2022-1471, CVE-2022-24823, CVE-2022-38752, CVE-2022-41854, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gh89210</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-reaper-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-reaper-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-reaper-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-reaper-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gh89210</guid>
    </item>
    <item>
      <title>EUVD-2026-163929</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-163929</link>
      <description>EUVD-2026-163929</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-163929</guid>
    </item>
    <item>
      <title>fkie_cve-2022-41854</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41854</link>
      <description>&lt;p&gt;Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-41854</guid>
    </item>
    <item>
      <title>GHSA-w37g-rhq8-7m4j — Snakeyaml vulnerable to Stack overflow leading to denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w37g-rhq8-7m4j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.yaml:snakeyaml&lt;/p&gt;
&lt;p&gt;Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.yaml:snakeyaml&lt;/p&gt;
&lt;p&gt;Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w37g-rhq8-7m4j</guid>
    </item>
    <item>
      <title>gsd-2022-41854</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-41854</link>
      <description>gsd-2022-41854</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-41854</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-41854 — Stack Overflow in Snakeyaml</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-41854</link>
      <description>msrc_CVE-2022-41854</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-41854</guid>
    </item>
    <item>
      <title>OESA-2023-1162 — snakeyaml security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1162</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: snakeyaml&lt;/p&gt;
&lt;p&gt;SnakeYAML is a YAML parser and emitter for the Java Virtual Machine. YAML is a data serialization format designed for human readability and interaction with scripting languages.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.(CVE-2022-25857)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38749)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38750)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38751)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.(CVE-2022-38752)&lt;/p&gt;
&lt;p&gt;Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: snakeyaml&lt;/p&gt;
&lt;p&gt;SnakeYAML is a YAML parser and emitter for the Java Virtual Machine. YAML is a data serialization format designed for human readability and interaction with scripting languages.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.(CVE-2022-25857)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38749)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38750)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38751)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.(CVE-2022-38752)&lt;/p&gt;
&lt;p&gt;Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1162</guid>
    </item>
    <item>
      <title>RHBA-2023:3300 — Red Hat Bug Fix Advisory: Release of Bug Advisories for the Jenkins image and Jenkins agent base image</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2023:3300</link>
      <description>&lt;p&gt;dev-java/snakeyaml: DoS via stack overflow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dev-java/snakeyaml: DoS via stack overflow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2023:3300</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2022-41854</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41854</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: snakeyaml, Ubuntu:Pro:16.04:LTS: snakeyaml, Ubuntu:Pro:18.04:LTS: snakeyaml, Ubuntu:20.04:LTS: snakeyaml, Ubuntu:22.04:LTS: snakeyaml, Ubuntu:24.10: snakeyaml, Ubuntu:24.04:LTS: snakeyaml&lt;/p&gt;
&lt;p&gt;Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: snakeyaml, Ubuntu:Pro:16.04:LTS: snakeyaml, Ubuntu:Pro:18.04:LTS: snakeyaml, Ubuntu:20.04:LTS: snakeyaml, Ubuntu:22.04:LTS: snakeyaml, Ubuntu:24.10: snakeyaml, Ubuntu:24.04:LTS: snakeyaml&lt;/p&gt;
&lt;p&gt;Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41854</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0416 — Red Hat OpenShift: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0416</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0416</guid>
    </item>
  </channel>
</rss>
