<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:35:09 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:2132 — Moderate: fence-agents security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:2132</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: fence-agents-aliyun, AlmaLinux:9: fence-agents-all, AlmaLinux:9: fence-agents-amt-ws, AlmaLinux:9: fence-agents-apc, AlmaLinux:9: fence-agents-apc-snmp, AlmaLinux:9: fence-agents-aws, AlmaLinux:9: fence-agents-azure-arm, AlmaLinux:9: fence-agents-bladecenter, AlmaLinux:9: fence-agents-brocade, AlmaLinux:9: fence-agents-cisco-mds and 45 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* urllib3: Request body not stripped after redirect from 303 status changes request method to GET (CVE-2023-45803)
* pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex (CVE-2023-52323)
* jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: fence-agents-aliyun, AlmaLinux:9: fence-agents-all, AlmaLinux:9: fence-agents-amt-ws, AlmaLinux:9: fence-agents-apc, AlmaLinux:9: fence-agents-apc-snmp, AlmaLinux:9: fence-agents-aws, AlmaLinux:9: fence-agents-azure-arm, AlmaLinux:9: fence-agents-bladecenter, AlmaLinux:9: fence-agents-brocade, AlmaLinux:9: fence-agents-cisco-mds and 45 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* urllib3: Request body not stripped after redirect from 303 status changes request method to GET (CVE-2023-45803)
* pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex (CVE-2023-52323)
* jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:2132</guid>
    </item>
    <item>
      <title>bdu:2024-00329</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00329</link>
      <description>bdu:2024-00329</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00329</guid>
    </item>
    <item>
      <title>BREW-animdl-CVE-2023-52323 — PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption</title>
      <link>https://cve.radiocsirt.org/vuln/brew-animdl-cve-2023-52323</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: animdl&lt;/p&gt;
&lt;p&gt;PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: animdl&lt;/p&gt;
&lt;p&gt;PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-animdl-cve-2023-52323</guid>
    </item>
    <item>
      <title>EUVD-2026-242742</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-242742</link>
      <description>EUVD-2026-242742</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-242742</guid>
    </item>
    <item>
      <title>fkie_cve-2023-52323</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-52323</link>
      <description>&lt;p&gt;PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-52323</guid>
    </item>
    <item>
      <title>GHSA-j225-cvw7-qrx7 — PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j225-cvw7-qrx7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pycryptodomex, PyPI: pycryptodome&lt;/p&gt;
&lt;p&gt;PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pycryptodomex, PyPI: pycryptodome&lt;/p&gt;
&lt;p&gt;PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j225-cvw7-qrx7</guid>
    </item>
    <item>
      <title>gsd-2023-52323</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-52323</link>
      <description>gsd-2023-52323</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-52323</guid>
    </item>
    <item>
      <title>OESA-2024-1046 — python-pycryptodome security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1046</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-pycryptodome, openEuler:20.03-LTS-SP4: python-pycryptodome, openEuler:22.03-LTS: python-pycryptodome, openEuler:22.03-LTS-SP1: python-pycryptodome, openEuler:22.03-LTS-SP2: python-pycryptodome, openEuler:22.03-LTS-SP3: python-pycryptodome&lt;/p&gt;
&lt;p&gt;PyCryptodome is a self-contained Python package of low-level cryptographic primitives. It supports Python 2.6 and 2.7, Python 3.4 and newer, and PyPy. You can install it with::     pip install pycryptodome All modules are installed under the ``Crypto`` package. Check the pycryptodomex_ project for the equivalent library that works under the ``Cryptodome`` package. PyCryptodome is a fork of PyCrypto. It brings several enhancements with respect to the last official version of PyCrypto (2.6.1), for instance: * Authenticated encryption modes (GCM, CCM, EAX, SIV, OCB) * Accelerated AES on Intel platforms via AES-NI * First class support for PyPy * Elliptic curves cryptography (NIST P-256, P-384 and P-521 curves only) * Better and more compact API (`nonce` and `iv` attributes for ciphers,   automatic generation of random nonces and IVs, simplified CTR cipher mode,   and more) * SHA-3 (including SHAKE XOFs) and BLAKE2 hash algorithms * Salsa20 and ChaCha20 stream ciphers * scrypt and HKDF * Deterministic (EC)DSA * Password-protected PKCS#8 key containers * Shamir&amp;amp;apos;s Secret Sharing scheme * Random numbers get sourced directly from the OS (and not from a CSPRNG in userspace) * Simplified install process, including better support for Windows * Cleaner RSA and DSA key generation (largely based on FIPS 186-4) * Major clean ups and simplification of the code base PyCryptodome is not a wrapper to a separate C library like *OpenSSL*. To the largest possible extent, algorithms are imple…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-pycryptodome, openEuler:20.03-LTS-SP4: python-pycryptodome, openEuler:22.03-LTS: python-pycryptodome, openEuler:22.03-LTS-SP1: python-pycryptodome, openEuler:22.03-LTS-SP2: python-pycryptodome, openEuler:22.03-LTS-SP3: python-pycryptodome&lt;/p&gt;
&lt;p&gt;PyCryptodome is a self-contained Python package of low-level cryptographic primitives. It supports Python 2.6 and 2.7, Python 3.4 and newer, and PyPy. You can install it with::     pip install pycryptodome All modules are installed under the ``Crypto`` package. Check the pycryptodomex_ project for the equivalent library that works under the ``Cryptodome`` package. PyCryptodome is a fork of PyCrypto. It brings several enhancements with respect to the last official version of PyCrypto (2.6.1), for instance: * Authenticated encryption modes (GCM, CCM, EAX, SIV, OCB) * Accelerated AES on Intel platforms via AES-NI * First class support for PyPy * Elliptic curves cryptography (NIST P-256, P-384 and P-521 curves only) * Better and more compact API (`nonce` and `iv` attributes for ciphers,   automatic generation of random nonces and IVs, simplified CTR cipher mode,   and more) * SHA-3 (including SHAKE XOFs) and BLAKE2 hash algorithms * Salsa20 and ChaCha20 stream ciphers * scrypt and HKDF * Deterministic (EC)DSA * Password-protected PKCS#8 key containers * Shamir&amp;amp;apos;s Secret Sharing scheme * Random numbers get sourced directly from the OS (and not from a CSPRNG in userspace) * Simplified install process, including better support for Windows * Cleaner RSA and DSA key generation (largely based on FIPS 186-4) * Major clean ups and simplification of the code base PyCryptodome is not a wrapper to a separate C library like *OpenSSL*. To the largest possible extent, algorithms are imple…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1046</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13567-1 — python310-pycryptodome-3.19.1-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13567-1</link>
      <description>&lt;p&gt;python310-pycryptodome-3.19.1-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-pycryptodome-3.19.1-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13567-1</guid>
    </item>
    <item>
      <title>PYSEC-2024-3</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2024-3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pycryptodomex&lt;/p&gt;
&lt;p&gt;PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pycryptodomex&lt;/p&gt;
&lt;p&gt;PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2024-3</guid>
    </item>
    <item>
      <title>RHBA-2024:1091 — Red Hat Bug Fix Advisory: fence-agents bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:1091</link>
      <description>&lt;p&gt;urllib3: Request body not stripped after redirect from 303 status changes request method to GET pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex jinja2: HTML attribute injection when passing user input as keys to xmlattr filter&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;urllib3: Request body not stripped after redirect from 303 status changes request method to GET pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex jinja2: HTML attribute injection when passing user input as keys to xmlattr filter&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:1091</guid>
    </item>
    <item>
      <title>SUSE-RU-2024:1829-2 — Recommended update for python-aliyun-python-sdk, python-aliyun-python-sdk-aas, python-aliyun-python-sdk-acm, python-ali…</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2024:1829-2</link>
      <description>&lt;p&gt;Recommended update for python-aliyun-python-sdk, python-aliyun-python-sdk-aas, python-aliyun-python-sdk-acm, python-aliyun-python-sdk-acms-open, python-aliyun-python-sdk-actiontrail, python-aliyun-python-sdk-adb, python-aliyun-python-sdk-adcp, python-aliyun-python-sdk-address-purification, python-aliyun-python-sdk-aegis, python-aliyun-python-sdk-afs, python-aliyun-python-sdk-aigen, python-aliyun-python-sdk-aimiaobi, python-aliyun-python-sdk-airec, python-aliyun-python-sdk-airticketopen, python-aliyun-python-sdk-alb, python-aliyun-python-sdk-alidns, python-aliyun-python-sdk-aligreen-console, python-aliyun-python-sdk-alikafka, python-aliyun-python-sdk-alimt, python-aliyun-python-sdk-alinlp, python-aliyun-python-sdk-aliyuncvc, python-aliyun-python-sdk-amptest, python-aliyun-python-sdk-amqp-open, python-aliyun-python-sdk-antiddos-public, python-aliyun-python-sdk-apds&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for python-aliyun-python-sdk, python-aliyun-python-sdk-aas, python-aliyun-python-sdk-acm, python-aliyun-python-sdk-acms-open, python-aliyun-python-sdk-actiontrail, python-aliyun-python-sdk-adb, python-aliyun-python-sdk-adcp, python-aliyun-python-sdk-address-purification, python-aliyun-python-sdk-aegis, python-aliyun-python-sdk-afs, python-aliyun-python-sdk-aigen, python-aliyun-python-sdk-aimiaobi, python-aliyun-python-sdk-airec, python-aliyun-python-sdk-airticketopen, python-aliyun-python-sdk-alb, python-aliyun-python-sdk-alidns, python-aliyun-python-sdk-aligreen-console, python-aliyun-python-sdk-alikafka, python-aliyun-python-sdk-alimt, python-aliyun-python-sdk-alinlp, python-aliyun-python-sdk-aliyuncvc, python-aliyun-python-sdk-amptest, python-aliyun-python-sdk-amqp-open, python-aliyun-python-sdk-antiddos-public, python-aliyun-python-sdk-apds&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2024:1829-2</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-52323</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52323</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: pycryptodome, Ubuntu:20.04:LTS: pycryptodome, Ubuntu:22.04:LTS: pycryptodome&lt;/p&gt;
&lt;p&gt;PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: pycryptodome, Ubuntu:20.04:LTS: pycryptodome, Ubuntu:22.04:LTS: pycryptodome&lt;/p&gt;
&lt;p&gt;PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52323</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0522 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0522</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, Phishing-Angriffe durchzuführen oder Cross-Site Scripting (XSS)-Angriffe auszuführen. Einige dieser Schwachstellen erfordern eine Benutzerinteraktion, um sie erfolgreich auszunutzen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, Phishing-Angriffe durchzuführen oder Cross-Site Scripting (XSS)-Angriffe auszuführen. Einige dieser Schwachstellen erfordern eine Benutzerinteraktion, um sie erfolgreich auszunutzen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0522</guid>
    </item>
  </channel>
</rss>
