<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:34:19 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-03945</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-03945</link>
      <description>bdu:2025-03945</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-03945</guid>
    </item>
    <item>
      <title>BREW-aws-sam-cli-CVE-2023-46136 — Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2023-46136</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aws-sam-cli&lt;/p&gt;
&lt;p&gt;Werkzeug multipart data parser needs to find a boundary that may be between consecutive chunks. That&amp;#39;s why parsing is based on looking for newline characters. Unfortunately, code looking for partial boundary in the buffer is written inefficiently, so if we upload a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer.&lt;/p&gt;
&lt;p&gt;This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. The amount of RAM required can trigger an out of memory kill of the process. If many concurrent requests are sent continuously, this can exhaust or kill all available workers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aws-sam-cli&lt;/p&gt;
&lt;p&gt;Werkzeug multipart data parser needs to find a boundary that may be between consecutive chunks. That&amp;#39;s why parsing is based on looking for newline characters. Unfortunately, code looking for partial boundary in the buffer is written inefficiently, so if we upload a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer.&lt;/p&gt;
&lt;p&gt;This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. The amount of RAM required can trigger an out of memory kill of the process. If many concurrent requests are sent continuously, this can exhaust or kill all available workers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2023-46136</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0074 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0074</link>
      <description>certfr-2024-avi-0074</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0074</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AZ09261 — Security fixes for CVE-2023-46136, CVE-2024-12797, CVE-2024-34069, CVE-2024-49766, CVE-2024-49767, CVE-2025-62727, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the airflow-3 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the airflow-3 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261</guid>
    </item>
    <item>
      <title>EUVD-2026-319774</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319774</link>
      <description>EUVD-2026-319774</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319774</guid>
    </item>
    <item>
      <title>fkie_cve-2023-46136</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46136</link>
      <description>&lt;p&gt;Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1 and 2.3.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1 and 2.3.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-46136</guid>
    </item>
    <item>
      <title>GHSA-hrfv-mqp8-q5rw — Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hrfv-mqp8-q5rw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Werkzeug&lt;/p&gt;
&lt;p&gt;Werkzeug multipart data parser needs to find a boundary that may be between consecutive chunks. That&amp;#39;s why parsing is based on looking for newline characters. Unfortunately, code looking for partial boundary in the buffer is written inefficiently, so if we upload a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer.&lt;/p&gt;
&lt;p&gt;This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. The amount of RAM required can trigger an out of memory kill of the process. If many concurrent requests are sent continuously, this can exhaust or kill all available workers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Werkzeug&lt;/p&gt;
&lt;p&gt;Werkzeug multipart data parser needs to find a boundary that may be between consecutive chunks. That&amp;#39;s why parsing is based on looking for newline characters. Unfortunately, code looking for partial boundary in the buffer is written inefficiently, so if we upload a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer.&lt;/p&gt;
&lt;p&gt;This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. The amount of RAM required can trigger an out of memory kill of the process. If many concurrent requests are sent continuously, this can exhaust or kill all available workers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hrfv-mqp8-q5rw</guid>
    </item>
    <item>
      <title>gsd-2023-46136</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-46136</link>
      <description>gsd-2023-46136</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-46136</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-46136 — Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF characte…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-46136</link>
      <description>msrc_CVE-2023-46136</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-46136</guid>
    </item>
    <item>
      <title>OESA-2025-1996 — python-werkzeug security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1996</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: python-werkzeug&lt;/p&gt;
&lt;p&gt;A comprehensive WSGI web application library&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1.(CVE-2023-46136)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: python-werkzeug&lt;/p&gt;
&lt;p&gt;A comprehensive WSGI web application library&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1.(CVE-2023-46136)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1996</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13375-1 — python310-Werkzeug-3.0.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13375-1</link>
      <description>&lt;p&gt;python310-Werkzeug-3.0.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-Werkzeug-3.0.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13375-1</guid>
    </item>
    <item>
      <title>PYSEC-2023-221</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2023-221</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: werkzeug&lt;/p&gt;
&lt;p&gt;Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: werkzeug&lt;/p&gt;
&lt;p&gt;Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2023-221</guid>
    </item>
    <item>
      <title>RHSA-2023:7473 — Red Hat Security Advisory: OpenShift Container Platform 4.14.4 packages and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:7473</link>
      <description>&lt;p&gt;python-werkzeug: high resource usage when parsing multipart form data with many fields haproxy: Proxy forwards malformed empty Content-Length headers python-werkzeug: high resource consumption leading to denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-werkzeug: high resource usage when parsing multipart form data with many fields haproxy: Proxy forwards malformed empty Content-Length headers python-werkzeug: high resource consumption leading to denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:7473</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3024 — Red Hat OpenShift: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3024</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3024</guid>
    </item>
  </channel>
</rss>
