<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:11:22 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-07911</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07911</link>
      <description>bdu:2023-07911</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07911</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0145 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</link>
      <description>certfr-2024-avi-0145</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EP15881 — Security fixes in cert-manager-webhook-pdns-fips 2.3.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ep15881</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cert-manager-webhook-pdns-fips&lt;/p&gt;
&lt;p&gt;Package cert-manager-webhook-pdns-fips version 2.3.0-r0 fixes 17 vulnerabilities: CVE-2022-1996, CVE-2023-45142, CVE-2023-25151, CVE-2022-21698, CVE-2022-30636...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cert-manager-webhook-pdns-fips&lt;/p&gt;
&lt;p&gt;Package cert-manager-webhook-pdns-fips version 2.3.0-r0 fixes 17 vulnerabilities: CVE-2022-1996, CVE-2023-45142, CVE-2023-25151, CVE-2022-21698, CVE-2022-30636...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ep15881</guid>
    </item>
    <item>
      <title>EUVD-2026-216878</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216878</link>
      <description>EUVD-2026-216878</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216878</guid>
    </item>
    <item>
      <title>fkie_cve-2023-45142</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-45142</link>
      <description>&lt;p&gt;OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server&amp;#39;s potential memory exhaustion when many malicious requests are sent to it. HTTP header User-Agent or HTTP method for requests can be easily set by an attacker to be random and long. The library internally uses `httpconv.ServerRequest` that records every value for HTTP `method` and `User-Agent`. In order to be affected, a program has to use the `otelhttp.NewHandler` wrapper and not filter any unknown HTTP methods or User agents on the level of CDN, LB, previous middleware, etc. Version 0.44.0 fixed this issue when the values collected for attribute `http.request.method` were changed to be restricted to a set of well-known values and other high cardinality attributes were removed. As a workaround to stop being affected, `otelhttp.WithFilter()` can be used, but it requires manual careful configuration to not log certain requests entirely. For convenience and safe usage of this library, it should by default mark with the label `unknown` non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server&amp;#39;s potential memory exhaustion when many malicious requests are sent to it. HTTP header User-Agent or HTTP method for requests can be easily set by an attacker to be random and long. The library internally uses `httpconv.ServerRequest` that records every value for HTTP `method` and `User-Agent`. In order to be affected, a program has to use the `otelhttp.NewHandler` wrapper and not filter any unknown HTTP methods or User agents on the level of CDN, LB, previous middleware, etc. Version 0.44.0 fixed this issue when the values collected for attribute `http.request.method` were changed to be restricted to a set of well-known values and other high cardinality attributes were removed. As a workaround to stop being affected, `otelhttp.WithFilter()` can be used, but it requires manual careful configuration to not log certain requests entirely. For convenience and safe usage of this library, it should by default mark with the label `unknown` non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-45142</guid>
    </item>
    <item>
      <title>GHSA-rcjv-mgp8-qvmr — OpenTelemetry-Go Contrib vulnerable to denial of service in otelhttp due to unbound cardinality metrics</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rcjv-mgp8-qvmr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp, Go: go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful, Go: go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin, Go: go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux, Go: go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho, Go: go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron, Go: go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;This handler wrapper https://github.com/open-telemetry/opentelemetry-go-contrib/blob/5f7e6ad5a49b45df45f61a1deb29d7f1158032df/instrumentation/net/http/otelhttp/handler.go#L63-L65
out of the box adds labels&lt;/p&gt;
&lt;p&gt;- `http.user_agent`
- `http.method`&lt;/p&gt;
&lt;p&gt;that have unbound cardinality. It leads to the server&amp;#39;s potential memory exhaustion when many malicious requests are sent to it.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;HTTP header User-Agent or HTTP method for requests can be easily set by an attacker to be random and long. The library internally uses [httpconv.ServerRequest](https://github.com/open-telemetry/opentelemetry-go/blob/v1.12.0/semconv/internal/v2/http.go#L159) that records every value for HTTP [method](https://github.com/open-telemetry/opentelemetry-go/blob/38e1b499c3da3107694ad2660b3888eee9c8b896/semconv/internal/v2/http.go#L204) and [User-Agent](https://github.com/open-telemetry/opentelemetry-go/blob/38e1b499c3da3107694ad2660b3888eee9c8b896/semconv/internal/v2/http.go#L223).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Send many requests with long randomly generated HTTP methods or/and User agents (e.g. a million) and observe how memory consumption increases during it.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In order to be affected, the program has to configure a metrics pipeline, use [otelhttp.NewHandler](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/5f7e6ad5a49b45df45f61a1deb29d7f1158032df/instrumentation/net/http/otelhttp/handler.go#L63-L65) wrapper, and does not filter any unknown HTTP methods or User agents on the level o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp, Go: go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful, Go: go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin, Go: go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux, Go: go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho, Go: go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron, Go: go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;This handler wrapper https://github.com/open-telemetry/opentelemetry-go-contrib/blob/5f7e6ad5a49b45df45f61a1deb29d7f1158032df/instrumentation/net/http/otelhttp/handler.go#L63-L65
out of the box adds labels&lt;/p&gt;
&lt;p&gt;- `http.user_agent`
- `http.method`&lt;/p&gt;
&lt;p&gt;that have unbound cardinality. It leads to the server&amp;#39;s potential memory exhaustion when many malicious requests are sent to it.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;HTTP header User-Agent or HTTP method for requests can be easily set by an attacker to be random and long. The library internally uses [httpconv.ServerRequest](https://github.com/open-telemetry/opentelemetry-go/blob/v1.12.0/semconv/internal/v2/http.go#L159) that records every value for HTTP [method](https://github.com/open-telemetry/opentelemetry-go/blob/38e1b499c3da3107694ad2660b3888eee9c8b896/semconv/internal/v2/http.go#L204) and [User-Agent](https://github.com/open-telemetry/opentelemetry-go/blob/38e1b499c3da3107694ad2660b3888eee9c8b896/semconv/internal/v2/http.go#L223).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Send many requests with long randomly generated HTTP methods or/and User agents (e.g. a million) and observe how memory consumption increases during it.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In order to be affected, the program has to configure a metrics pipeline, use [otelhttp.NewHandler](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/5f7e6ad5a49b45df45f61a1deb29d7f1158032df/instrumentation/net/http/otelhttp/handler.go#L63-L65) wrapper, and does not filter any unknown HTTP methods or User agents on the level o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rcjv-mgp8-qvmr</guid>
    </item>
    <item>
      <title>gsd-2023-45142</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-45142</link>
      <description>gsd-2023-45142</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-45142</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-45142 — OpenTelemetry-Go Contrib has DoS vulnerability in otelhttp due to unbound cardinality metrics</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-45142</link>
      <description>msrc_CVE-2023-45142</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-45142</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0211-1 — Security update for caddy</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0211-1</link>
      <description>&lt;p&gt;Security update for caddy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for caddy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0211-1</guid>
    </item>
    <item>
      <title>RHBA-2023:7648 — Red Hat Bug Fix Advisory: MTV 2.5.3 Images</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2023:7648</link>
      <description>&lt;p&gt;golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake opentelemetry: DoS vulnerability in otelhttp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake opentelemetry: DoS vulnerability in otelhttp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2023:7648</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3188-1 — Security update for containerd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3188-1</link>
      <description>&lt;p&gt;Security update for containerd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for containerd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3188-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-45142</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-45142</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: golang-opentelemetry-contrib, Ubuntu:26.04:LTS: golang-opentelemetry-contrib&lt;/p&gt;
&lt;p&gt;OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server&amp;#39;s potential memory exhaustion when many malicious requests are sent to it. HTTP header User-Agent or HTTP method for requests can be easily set by an attacker to be random and long. The library internally uses `httpconv.ServerRequest` that records every value for HTTP `method` and `User-Agent`. In order to be affected, a program has to use the `otelhttp.NewHandler` wrapper and not filter any unknown HTTP methods or User agents on the level of CDN, LB, previous middleware, etc. Version 0.44.0 fixed this issue when the values collected for attribute `http.request.method` were changed to be restricted to a set of well-known values and other high cardinality attributes were removed. As a workaround to stop being affected, `otelhttp.WithFilter()` can be used, but it requires manual careful configuration to not log certain requests entirely. For convenience and safe usage of this library, it should by default mark with the label `unknown` non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: golang-opentelemetry-contrib, Ubuntu:26.04:LTS: golang-opentelemetry-contrib&lt;/p&gt;
&lt;p&gt;OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server&amp;#39;s potential memory exhaustion when many malicious requests are sent to it. HTTP header User-Agent or HTTP method for requests can be easily set by an attacker to be random and long. The library internally uses `httpconv.ServerRequest` that records every value for HTTP `method` and `User-Agent`. In order to be affected, a program has to use the `otelhttp.NewHandler` wrapper and not filter any unknown HTTP methods or User agents on the level of CDN, LB, previous middleware, etc. Version 0.44.0 fixed this issue when the values collected for attribute `http.request.method` were changed to be restricted to a set of well-known values and other high cardinality attributes were removed. As a workaround to stop being affected, `otelhttp.WithFilter()` can be used, but it requires manual careful configuration to not log certain requests entirely. For convenience and safe usage of this library, it should by default mark with the label `unknown` non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-45142</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3067 — Red Hat OpenShift: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3067</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen und um Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen und um Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3067</guid>
    </item>
  </channel>
</rss>
