<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:33:29 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-13518</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13518</link>
      <description>bdu:2025-13518</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13518</guid>
    </item>
    <item>
      <title>EUVD-2026-241991</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-241991</link>
      <description>EUVD-2026-241991</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-241991</guid>
    </item>
    <item>
      <title>fkie_cve-2024-12224</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-12224</link>
      <description>&lt;p&gt;Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-12224</guid>
    </item>
    <item>
      <title>GHSA-h97m-ww89-6jmq — `idna` accepts Punycode labels that do not produce any non-ASCII when decoded</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h97m-ww89-6jmq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: idna&lt;/p&gt;
&lt;p&gt;`idna` 0.5.0 and earlier accepts Punycode labels that do not produce any non-ASCII output, which means that either ASCII labels or the empty root label can be masked such that they appear unequal without IDNA processing or when processed with a different implementation and equal when processed with `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;Concretely, `example.org` and `xn--example-.org` become equal after processing by `idna` 0.5.0 or earlier. Also, `example.org.xn--` and `example.org.` become equal after processing by `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;In applications using `idna` (but not in `idna` itself) this may be able to lead to privilege escalation when host name comparison is part of a privilege check and the behavior is combined with a client that resolves domains with such labels instead of treating them as errors that preclude DNS resolution / URL fetching and with the attacker managing to introduce a DNS entry (and TLS certificate) for an `xn--`-masked name that turns into the name of the target when processed by `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;## Remedy&lt;/p&gt;
&lt;p&gt;Upgrade to `idna` 1.0.3 or later, if depending on `idna` directly, or to `url` 2.5.4 or later, if depending on `idna` via `url`. (This issue was fixed in `idna` 1.0.0, but versions earlier than 1.0.3 are not recommended for other reasons.)&lt;/p&gt;
&lt;p&gt;When upgrading, please take a moment to read about [alternative Unicode back ends for `idna`](https://docs.rs/crate/idna_adapter/latest).&lt;/p&gt;
&lt;p&gt;If you are using Rust earlier than 1.81 in combination with SQLx…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: idna&lt;/p&gt;
&lt;p&gt;`idna` 0.5.0 and earlier accepts Punycode labels that do not produce any non-ASCII output, which means that either ASCII labels or the empty root label can be masked such that they appear unequal without IDNA processing or when processed with a different implementation and equal when processed with `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;Concretely, `example.org` and `xn--example-.org` become equal after processing by `idna` 0.5.0 or earlier. Also, `example.org.xn--` and `example.org.` become equal after processing by `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;In applications using `idna` (but not in `idna` itself) this may be able to lead to privilege escalation when host name comparison is part of a privilege check and the behavior is combined with a client that resolves domains with such labels instead of treating them as errors that preclude DNS resolution / URL fetching and with the attacker managing to introduce a DNS entry (and TLS certificate) for an `xn--`-masked name that turns into the name of the target when processed by `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;## Remedy&lt;/p&gt;
&lt;p&gt;Upgrade to `idna` 1.0.3 or later, if depending on `idna` directly, or to `url` 2.5.4 or later, if depending on `idna` via `url`. (This issue was fixed in `idna` 1.0.0, but versions earlier than 1.0.3 are not recommended for other reasons.)&lt;/p&gt;
&lt;p&gt;When upgrading, please take a moment to read about [alternative Unicode back ends for `idna`](https://docs.rs/crate/idna_adapter/latest).&lt;/p&gt;
&lt;p&gt;If you are using Rust earlier than 1.81 in combination with SQLx…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h97m-ww89-6jmq</guid>
    </item>
    <item>
      <title>OESA-2026-2944 — rpm-ostree security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2944</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: rpm-ostree&lt;/p&gt;
&lt;p&gt;rpm-ostree is a hybrid image/package system.  It supports &amp;amp;amp;quot;composing&amp;amp;amp;quot; packages on a build server into an OSTree repository, which can then be replicated by client systems with atomic upgrades. Additionally, unlike many &amp;amp;amp;quot;pure&amp;amp;amp;quot; image systems, with rpm-ostree each client system can layer on additional packages, providing a &amp;amp;amp;quot;best of both worlds&amp;amp;amp;quot; approach.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.(CVE-2023-53159)&lt;/p&gt;
&lt;p&gt;Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.(CVE-2024-12224)&lt;/p&gt;
&lt;p&gt;A flaw was found in OpenSSL&amp;amp;apos;s handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string.(CVE-2025-3416)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: rpm-ostree&lt;/p&gt;
&lt;p&gt;rpm-ostree is a hybrid image/package system.  It supports &amp;amp;amp;quot;composing&amp;amp;amp;quot; packages on a build server into an OSTree repository, which can then be replicated by client systems with atomic upgrades. Additionally, unlike many &amp;amp;amp;quot;pure&amp;amp;amp;quot; image systems, with rpm-ostree each client system can layer on additional packages, providing a &amp;amp;amp;quot;best of both worlds&amp;amp;amp;quot; approach.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.(CVE-2023-53159)&lt;/p&gt;
&lt;p&gt;Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.(CVE-2024-12224)&lt;/p&gt;
&lt;p&gt;A flaw was found in OpenSSL&amp;amp;apos;s handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string.(CVE-2025-3416)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2944</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15201-1 — python311-nh3-0.2.17-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15201-1</link>
      <description>&lt;p&gt;python311-nh3-0.2.17-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-nh3-0.2.17-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15201-1</guid>
    </item>
    <item>
      <title>RHSA-2025:17340 — Red Hat Security Advisory: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:17340</link>
      <description>&lt;p&gt;idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded firefox: thunderbird: Sandbox escape due to use-after-free in the Graphics: Canvas2D component firefox: thunderbird: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component firefox: thunderbird: Same-origin policy bypass in the Layout component firefox: thunderbird: Incorrect boundary conditions in the JavaScript: GC component firefox: thunderbird: Integer overflow in the SVG component firefox: thunderbird: Information disclosure in the Networking: Cache component firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded firefox: thunderbird: Sandbox escape due to use-after-free in the Graphics: Canvas2D component firefox: thunderbird: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component firefox: thunderbird: Same-origin policy bypass in the Layout component firefox: thunderbird: Incorrect boundary conditions in the JavaScript: GC component firefox: thunderbird: Integer overflow in the SVG component firefox: thunderbird: Information disclosure in the Networking: Cache component firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:17340</guid>
    </item>
    <item>
      <title>RUSTSEC-2024-0421 — `idna` accepts Punycode labels that do not produce any non-ASCII when decoded</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2024-0421</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: idna&lt;/p&gt;
&lt;p&gt;`idna` 0.5.0 and earlier accepts Punycode labels that do not produce any non-ASCII output, which means that either ASCII labels or the empty root label can be masked such that they appear unequal without IDNA processing or when processed with a different implementation and equal when processed with `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;Concretely, `example.org` and `xn--example-.org` become equal after processing by `idna` 0.5.0 or earlier. Also, `example.org.xn--` and `example.org.` become equal after processing by `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;In applications using `idna` (but not in `idna` itself) this may be able to lead to privilege escalation when host name comparison is part of a privilege check and the behavior is combined with a client that resolves domains with such labels instead of treating them as errors that preclude DNS resolution / URL fetching and with the attacker managing to introduce a DNS entry (and TLS certificate) for an `xn--`-masked name that turns into the name of the target when processed by `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;## Remedy&lt;/p&gt;
&lt;p&gt;Upgrade to `idna` 1.0.3 or later, if depending on `idna` directly, or to `url` 2.5.4 or later, if depending on `idna` via `url`. (This issue was fixed in `idna` 1.0.0, but versions earlier than 1.0.3 are not recommended for other reasons.)&lt;/p&gt;
&lt;p&gt;When upgrading, please take a moment to read about [alternative Unicode back ends for `idna`](https://docs.rs/crate/idna_adapter/latest).&lt;/p&gt;
&lt;p&gt;If you are using Rust earlier than 1.81 in combination with SQLx…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: idna&lt;/p&gt;
&lt;p&gt;`idna` 0.5.0 and earlier accepts Punycode labels that do not produce any non-ASCII output, which means that either ASCII labels or the empty root label can be masked such that they appear unequal without IDNA processing or when processed with a different implementation and equal when processed with `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;Concretely, `example.org` and `xn--example-.org` become equal after processing by `idna` 0.5.0 or earlier. Also, `example.org.xn--` and `example.org.` become equal after processing by `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;In applications using `idna` (but not in `idna` itself) this may be able to lead to privilege escalation when host name comparison is part of a privilege check and the behavior is combined with a client that resolves domains with such labels instead of treating them as errors that preclude DNS resolution / URL fetching and with the attacker managing to introduce a DNS entry (and TLS certificate) for an `xn--`-masked name that turns into the name of the target when processed by `idna` 0.5.0 or earlier.&lt;/p&gt;
&lt;p&gt;## Remedy&lt;/p&gt;
&lt;p&gt;Upgrade to `idna` 1.0.3 or later, if depending on `idna` directly, or to `url` 2.5.4 or later, if depending on `idna` via `url`. (This issue was fixed in `idna` 1.0.0, but versions earlier than 1.0.3 are not recommended for other reasons.)&lt;/p&gt;
&lt;p&gt;When upgrading, please take a moment to read about [alternative Unicode back ends for `idna`](https://docs.rs/crate/idna_adapter/latest).&lt;/p&gt;
&lt;p&gt;If you are using Rust earlier than 1.81 in combination with SQLx…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2024-0421</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02809-1 — Security update for rust-keylime</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02809-1</link>
      <description>&lt;p&gt;Security update for rust-keylime&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rust-keylime&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02809-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-12224</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12224</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: rust-idna, Ubuntu:22.04:LTS: rust-idna, Ubuntu:24.04:LTS: rust-idna, Ubuntu:25.10: rust-idna, Ubuntu:26.04:LTS: rust-idna&lt;/p&gt;
&lt;p&gt;Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: rust-idna, Ubuntu:22.04:LTS: rust-idna, Ubuntu:24.04:LTS: rust-idna, Ubuntu:25.10: rust-idna, Ubuntu:26.04:LTS: rust-idna&lt;/p&gt;
&lt;p&gt;Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12224</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0686 — IBM DataPower Gateway: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0686</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM DataPower Gateway ausnutzen, um einen Denial of Service Angriff durchzuführen, oder seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM DataPower Gateway ausnutzen, um einen Denial of Service Angriff durchzuführen, oder seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0686</guid>
    </item>
  </channel>
</rss>
