<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:34:31 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-00588</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00588</link>
      <description>bdu:2024-00588</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00588</guid>
    </item>
    <item>
      <title>certfr-2023-avi-1007 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-1007</link>
      <description>certfr-2023-avi-1007</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-1007</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CU18187 — Security fixes in stargate 1.0.90-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cu18187</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Package stargate version 1.0.90-r4 fixes 87 vulnerabilities: ghsa-76h9-2vwh-w278, ghsa-pqr6-cmr2-h8hf, ghsa-fjpj-2g6w-x25r, ghsa-qcwq-55hx-v3vh, ghsa-55g7-9cwv-5qfv...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Package stargate version 1.0.90-r4 fixes 87 vulnerabilities: ghsa-76h9-2vwh-w278, ghsa-pqr6-cmr2-h8hf, ghsa-fjpj-2g6w-x25r, ghsa-qcwq-55hx-v3vh, ghsa-55g7-9cwv-5qfv...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cu18187</guid>
    </item>
    <item>
      <title>EUVD-2026-187480</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-187480</link>
      <description>EUVD-2026-187480</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-187480</guid>
    </item>
    <item>
      <title>fkie_cve-2023-43642</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-43642</link>
      <description>&lt;p&gt;snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-43642</guid>
    </item>
    <item>
      <title>GHSA-55g7-9cwv-5qfv — snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-55g7-9cwv-5qfv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xerial.snappy:snappy-java&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;snappy-java is a data compression library in Java. Its SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too-large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur.&lt;/p&gt;
&lt;p&gt;### Scope&lt;/p&gt;
&lt;p&gt;All versions of snappy-java including the latest released version 1.1.10.3.  A fix is applied in 1.1.10.4&lt;/p&gt;
&lt;p&gt;### Details
While performing mitigation efforts related to [CVE-2023-34455](https://nvd.nist.gov/vuln/detail/CVE-2023-34455) in Confluent products, our Application Security team closely analyzed the fix that was accepted and merged into snappy-java version 1.1.10.1 in [this](https://github.com/xerial/snappy-java/commit/3bf67857fcf70d9eea56eed4af7c925671e8eaea) commit. The check on [line 421](https://github.com/xerial/snappy-java/commit/3bf67857fcf70d9eea56eed4af7c925671e8eaea#diff-c3e53610267092989965e8c7dd2d4417d355ff7f560f9e8075b365f32569079fR421) only attempts to check if chunkSize is not a negative value. We believe that this is an inadequate fix as it misses an upper-bounds check for overly positive values such as 0x7FFFFFFF (or (2,147,483,647 in decimal) before actually [attempting to allocate](https://github.com/xerial/snappy-java/commit/3bf67857fcf70d9eea56eed4af7c925671e8eaea#diff-c3e53610267092989965e8c7dd2d4417d355ff7f560f9e8075b365f32569079fR429) the provided unverified number of bytes via the “chunkSize” variable. This missing upper-bounds check can lead to t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xerial.snappy:snappy-java&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;snappy-java is a data compression library in Java. Its SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too-large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur.&lt;/p&gt;
&lt;p&gt;### Scope&lt;/p&gt;
&lt;p&gt;All versions of snappy-java including the latest released version 1.1.10.3.  A fix is applied in 1.1.10.4&lt;/p&gt;
&lt;p&gt;### Details
While performing mitigation efforts related to [CVE-2023-34455](https://nvd.nist.gov/vuln/detail/CVE-2023-34455) in Confluent products, our Application Security team closely analyzed the fix that was accepted and merged into snappy-java version 1.1.10.1 in [this](https://github.com/xerial/snappy-java/commit/3bf67857fcf70d9eea56eed4af7c925671e8eaea) commit. The check on [line 421](https://github.com/xerial/snappy-java/commit/3bf67857fcf70d9eea56eed4af7c925671e8eaea#diff-c3e53610267092989965e8c7dd2d4417d355ff7f560f9e8075b365f32569079fR421) only attempts to check if chunkSize is not a negative value. We believe that this is an inadequate fix as it misses an upper-bounds check for overly positive values such as 0x7FFFFFFF (or (2,147,483,647 in decimal) before actually [attempting to allocate](https://github.com/xerial/snappy-java/commit/3bf67857fcf70d9eea56eed4af7c925671e8eaea#diff-c3e53610267092989965e8c7dd2d4417d355ff7f560f9e8075b365f32569079fR429) the provided unverified number of bytes via the “chunkSize” variable. This missing upper-bounds check can lead to t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-55g7-9cwv-5qfv</guid>
    </item>
    <item>
      <title>gsd-2023-43642</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-43642</link>
      <description>gsd-2023-43642</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-43642</guid>
    </item>
    <item>
      <title>OESA-2023-1700 — snappy-java security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1700</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: snappy-java, openEuler:20.03-LTS-SP3: snappy-java, openEuler:22.03-LTS: snappy-java, openEuler:22.03-LTS-SP1: snappy-java, openEuler:22.03-LTS-SP2: snappy-java&lt;/p&gt;
&lt;p&gt;A Java port of the snappy, a fast compresser/decompresser written in C++.&#13;
&#13;
Security Fix(es):&#13;
&#13;
snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.(CVE-2023-43642)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: snappy-java, openEuler:20.03-LTS-SP3: snappy-java, openEuler:22.03-LTS: snappy-java, openEuler:22.03-LTS-SP1: snappy-java, openEuler:22.03-LTS-SP2: snappy-java&lt;/p&gt;
&lt;p&gt;A Java port of the snappy, a fast compresser/decompresser written in C++.&#13;
&#13;
Security Fix(es):&#13;
&#13;
snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.(CVE-2023-43642)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1700</guid>
    </item>
    <item>
      <title>RHSA-2023:7612 — Red Hat Security Advisory: Red Hat build of Quarkus 3.2.9 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:7612</link>
      <description>&lt;p&gt;quarkus: GraphQL operations over WebSockets bypass apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK snappy-java: Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impact&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;quarkus: GraphQL operations over WebSockets bypass apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK snappy-java: Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impact&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:7612</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-43642</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43642</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: snappy-java, Ubuntu:16.04:LTS: snappy-java, Ubuntu:18.04:LTS: snappy-java, Ubuntu:20.04:LTS: snappy-java, Ubuntu:22.04:LTS: snappy-java, Ubuntu:24.04:LTS: snappy-java, Ubuntu:25.10: snappy-java, Ubuntu:26.04:LTS: snappy-java&lt;/p&gt;
&lt;p&gt;snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: snappy-java, Ubuntu:16.04:LTS: snappy-java, Ubuntu:18.04:LTS: snappy-java, Ubuntu:20.04:LTS: snappy-java, Ubuntu:22.04:LTS: snappy-java, Ubuntu:24.04:LTS: snappy-java, Ubuntu:25.10: snappy-java, Ubuntu:26.04:LTS: snappy-java&lt;/p&gt;
&lt;p&gt;snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43642</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2935 — IBM Integration Bus: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2935</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM Integration Bus ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM Integration Bus ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2935</guid>
    </item>
  </channel>
</rss>
