<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:44:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-188474</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-188474</link>
      <description>EUVD-2026-188474</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-188474</guid>
    </item>
    <item>
      <title>fkie_cve-2023-32187</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-32187</link>
      <description>&lt;p&gt;An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers&amp;#39; apiserver/supervisor port (TCP 6443) cause denial of service.
This issue affects k3s: from v1.24.0 before v1.24.17+k3s1, from v1.25.0 before v1.25.13+k3s1, from v1.26.0 before v1.26.8+k3s1, from sev1.27.0 before v1.27.5+k3s1, from v1.28.0 before v1.28.1+k3s1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers&amp;#39; apiserver/supervisor port (TCP 6443) cause denial of service.
This issue affects k3s: from v1.24.0 before v1.24.17+k3s1, from v1.25.0 before v1.25.13+k3s1, from v1.26.0 before v1.26.8+k3s1, from sev1.27.0 before v1.27.5+k3s1, from v1.28.0 before v1.28.1+k3s1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-32187</guid>
    </item>
    <item>
      <title>GHSA-m4hf-6vgr-75r2 — K3s apiserver port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m4hf-6vgr-75r2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/k3s-io/k3s&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An issue was found in K3s where an attacker with network access to K3s servers&amp;#39; apiserver/supervisor port (TCP 6443) can force the TLS server to add entries to the certificate&amp;#39;s Subject Alternative Name (SAN) list, through a stuffing attack, until the certificate grows so large that it exceeds the maximum size allowed by TLS client implementations. OpenSSL for example will raise an `excessive message size` error when this occurs. No authentication is necessary to perform this attack, only the ability to perform a TLS handshake against the apiserver/supervisor port (TCP 6443).&lt;/p&gt;
&lt;p&gt;Affected servers will continue to operate, but clients (including both external administrative access with `kubectl` and server or agent nodes) will fail to establish new connections, thus leading to a denial of service (DoS) attack.&lt;/p&gt;
&lt;p&gt;### Remediation&lt;/p&gt;
&lt;p&gt;Upgrade to a fixed release:&lt;/p&gt;
&lt;p&gt;- v1.28.1+k3s1
- v1.27.5+k3s1
- v1.26.8+k3s1
- v1.25.13+k3s1
- v1.24.17+k3s1&lt;/p&gt;
&lt;p&gt;If you are using K3s 1.27 or earlier, you must also add  the parameter `tls-san-security: true` to the K3s configuration to enable enhanced security for the supervisor&amp;#39;s TLS SAN list. This option defaults to `true` starting with K3s 1.28.&lt;/p&gt;
&lt;p&gt;Note that this flag changes the behavior of K3s servers. You should ensure that you configure `node-external-ip` on servers that will be connected to via an external IP, and add `tls-san` entries for any load-balancers or VIP addresses that will be associated with the supervisor port. External IPs and l…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/k3s-io/k3s&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An issue was found in K3s where an attacker with network access to K3s servers&amp;#39; apiserver/supervisor port (TCP 6443) can force the TLS server to add entries to the certificate&amp;#39;s Subject Alternative Name (SAN) list, through a stuffing attack, until the certificate grows so large that it exceeds the maximum size allowed by TLS client implementations. OpenSSL for example will raise an `excessive message size` error when this occurs. No authentication is necessary to perform this attack, only the ability to perform a TLS handshake against the apiserver/supervisor port (TCP 6443).&lt;/p&gt;
&lt;p&gt;Affected servers will continue to operate, but clients (including both external administrative access with `kubectl` and server or agent nodes) will fail to establish new connections, thus leading to a denial of service (DoS) attack.&lt;/p&gt;
&lt;p&gt;### Remediation&lt;/p&gt;
&lt;p&gt;Upgrade to a fixed release:&lt;/p&gt;
&lt;p&gt;- v1.28.1+k3s1
- v1.27.5+k3s1
- v1.26.8+k3s1
- v1.25.13+k3s1
- v1.24.17+k3s1&lt;/p&gt;
&lt;p&gt;If you are using K3s 1.27 or earlier, you must also add  the parameter `tls-san-security: true` to the K3s configuration to enable enhanced security for the supervisor&amp;#39;s TLS SAN list. This option defaults to `true` starting with K3s 1.28.&lt;/p&gt;
&lt;p&gt;Note that this flag changes the behavior of K3s servers. You should ensure that you configure `node-external-ip` on servers that will be connected to via an external IP, and add `tls-san` entries for any load-balancers or VIP addresses that will be associated with the supervisor port. External IPs and l…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m4hf-6vgr-75r2</guid>
    </item>
    <item>
      <title>gsd-2023-32187</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-32187</link>
      <description>gsd-2023-32187</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-32187</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2303 — Kubernetes: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2303</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2303</guid>
    </item>
  </channel>
</rss>
