<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:54:29 +0000</lastBuildDate>
    <item>
      <title>BIT-nats-2023-46129 — xkeys Seal encryption used fixed key for all encryption</title>
      <link>https://cve.radiocsirt.org/vuln/bit-nats-2023-46129</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: nats&lt;/p&gt;
&lt;p&gt;NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library&amp;#39;s `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing.  
FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: nats&lt;/p&gt;
&lt;p&gt;NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library&amp;#39;s `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing.  
FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-nats-2023-46129</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0756 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</link>
      <description>certfr-2025-avi-0756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-JI58569 — Security fix for CVE-2023-46129 applied in: nats-server-fips 2.10.4-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ji58569</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nats-server-fips&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the nats-server-fips package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nats-server-fips&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the nats-server-fips package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ji58569</guid>
    </item>
    <item>
      <title>EUVD-2026-219599</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-219599</link>
      <description>EUVD-2026-219599</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-219599</guid>
    </item>
    <item>
      <title>fkie_cve-2023-46129</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46129</link>
      <description>&lt;p&gt;NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library&amp;#39;s `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing.  
FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library&amp;#39;s `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing.  
FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-46129</guid>
    </item>
    <item>
      <title>GHSA-mr45-rx8q-wcm9 — xkeys seal encryption used fixed key for all encryption</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mr45-rx8q-wcm9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/nats-io/nkeys, Go: github.com/nats-io/nats-server/v2&lt;/p&gt;
&lt;p&gt;## Background&lt;/p&gt;
&lt;p&gt;NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.&lt;/p&gt;
&lt;p&gt;The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication.  This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts.&lt;/p&gt;
&lt;p&gt;## Problem Description&lt;/p&gt;
&lt;p&gt;The nkeys library&amp;#39;s &amp;#34;xkeys&amp;#34; encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use.  As a result, all encryption was actually to an all-zeros key.&lt;/p&gt;
&lt;p&gt;This affects encryption only, not signing.  
FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY.&lt;/p&gt;
&lt;p&gt;## Affected versions&lt;/p&gt;
&lt;p&gt;nkeys Go library:
 * 0.4.0 up to and including 0.4.5
 * Fixed with nats-io/nkeys: 0.4.6&lt;/p&gt;
&lt;p&gt;NATS Server:
 * 2.10.0 up to and including 2.10.3
 * Fixed with nats-io/nats-server: 2.10.4&lt;/p&gt;
&lt;p&gt;## Solution&lt;/p&gt;
&lt;p&gt;Upgrade the nats-server.  
For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Problem reported by Quentin Matillat (GitHub @tinou98).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/nats-io/nkeys, Go: github.com/nats-io/nats-server/v2&lt;/p&gt;
&lt;p&gt;## Background&lt;/p&gt;
&lt;p&gt;NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.&lt;/p&gt;
&lt;p&gt;The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication.  This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts.&lt;/p&gt;
&lt;p&gt;## Problem Description&lt;/p&gt;
&lt;p&gt;The nkeys library&amp;#39;s &amp;#34;xkeys&amp;#34; encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use.  As a result, all encryption was actually to an all-zeros key.&lt;/p&gt;
&lt;p&gt;This affects encryption only, not signing.  
FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY.&lt;/p&gt;
&lt;p&gt;## Affected versions&lt;/p&gt;
&lt;p&gt;nkeys Go library:
 * 0.4.0 up to and including 0.4.5
 * Fixed with nats-io/nkeys: 0.4.6&lt;/p&gt;
&lt;p&gt;NATS Server:
 * 2.10.0 up to and including 2.10.3
 * Fixed with nats-io/nats-server: 2.10.4&lt;/p&gt;
&lt;p&gt;## Solution&lt;/p&gt;
&lt;p&gt;Upgrade the nats-server.  
For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Problem reported by Quentin Matillat (GitHub @tinou98).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mr45-rx8q-wcm9</guid>
    </item>
    <item>
      <title>gsd-2023-46129</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-46129</link>
      <description>gsd-2023-46129</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-46129</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-46129 — xkeys Seal encryption used fixed key for all encryption</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-46129</link>
      <description>msrc_CVE-2023-46129</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-46129</guid>
    </item>
    <item>
      <title>RHSA-2023:7663 — Red Hat Security Advisory: Red Hat OpenShift distributed tracing 3.0.0 operator/operand containers</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:7663</link>
      <description>&lt;p&gt;opentelemetry: DoS vulnerability in otelhttp nkeys: xkeys Seal encryption used fixed key for all encryption&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;opentelemetry: DoS vulnerability in otelhttp nkeys: xkeys Seal encryption used fixed key for all encryption&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:7663</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-46129</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46129</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: golang-github-nats-io-nkeys, Ubuntu:22.04:LTS: golang-github-nats-io-nkeys&lt;/p&gt;
&lt;p&gt;NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library&amp;#39;s `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing. FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: golang-github-nats-io-nkeys, Ubuntu:22.04:LTS: golang-github-nats-io-nkeys&lt;/p&gt;
&lt;p&gt;NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library&amp;#39;s `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing. FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46129</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3067 — Red Hat OpenShift: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3067</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen und um Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen und um Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3067</guid>
    </item>
  </channel>
</rss>
