<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:55:56 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:0150 — Important: .NET 8.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:0150</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-host, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-targeting-pack-8.0 and 2 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.101 and .NET Runtime 8.0.1.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) (CVE-2024-0056)
* dotnet: X509 Certificates - Validation Bypass across Azure (CVE-2024-0057)
* dotnet: .NET Denial of Service Vulnerability (CVE-2024-21319)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-host, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-targeting-pack-8.0 and 2 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.101 and .NET Runtime 8.0.1.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) (CVE-2024-0056)
* dotnet: X509 Certificates - Validation Bypass across Azure (CVE-2024-0057)
* dotnet: .NET Denial of Service Vulnerability (CVE-2024-21319)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:0150</guid>
    </item>
    <item>
      <title>bdu:2024-00642</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00642</link>
      <description>bdu:2024-00642</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00642</guid>
    </item>
    <item>
      <title>BIT-dotnet-2024-21319 — Microsoft Identity Denial of service vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/bit-dotnet-2024-21319</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: dotnet&lt;/p&gt;
&lt;p&gt;Microsoft Identity Denial of service vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: dotnet&lt;/p&gt;
&lt;p&gt;Microsoft Identity Denial of service vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-dotnet-2024-21319</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0022 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Microsoft .Net&lt;/span&gt;. Elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0022</link>
      <description>certfr-2024-avi-0022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0022</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-WW90034 — Microsoft Identity Denial of service vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-ww90034</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: dotnet6-build, CleanStart: dotnet6-runtime&lt;/p&gt;
&lt;p&gt;CVE-2024-21319 affects multiple packages. Microsoft Identity Denial of service vulnerability See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: dotnet6-build, CleanStart: dotnet6-runtime&lt;/p&gt;
&lt;p&gt;CVE-2024-21319 affects multiple packages. Microsoft Identity Denial of service vulnerability See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-ww90034</guid>
    </item>
    <item>
      <title>EUVD-2026-242679</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-242679</link>
      <description>EUVD-2026-242679</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-242679</guid>
    </item>
    <item>
      <title>fkie_cve-2024-21319</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-21319</link>
      <description>&lt;p&gt;Microsoft Identity Denial of service vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Microsoft Identity Denial of service vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-21319</guid>
    </item>
    <item>
      <title>GHSA-59j7-ghrg-fj52 — Microsoft ASP.NET Core project templates vulnerable to denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-59j7-ghrg-fj52</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: System.IdentityModel.Tokens.Jwt, NuGet: Microsoft.IdentityModel.JsonWebTokens&lt;/p&gt;
&lt;p&gt;A Denial of Service vulnerability exists in ASP.NET Core project templates which utilize JWT-based authentication tokens. This vulnerability allows an unauthenticated client to consume arbitrarily large amounts of server memory, potentially triggering an out-of-memory condition on the server and making the server no longer able to respond to legitimate requests.&lt;/p&gt;
&lt;p&gt;## Announcement&lt;/p&gt;
&lt;p&gt;Announcement for this issue can be found at  https://github.com/dotnet/announcements/issues/290&lt;/p&gt;
&lt;p&gt;### Mitigation factors&lt;/p&gt;
&lt;p&gt;This impacts only .NET Core-based projects that were created using any version of project templates listed in affected software. 
Other project templates e.g., console applications, MAUI applications, Windows Forms or WPF applications, are not affected.&lt;/p&gt;
&lt;p&gt;## Affected software&lt;/p&gt;
&lt;p&gt;This impacts only .NET Core-based projects that were created using any version of the below project templates.&lt;/p&gt;
&lt;p&gt;-	ASP.NET Core Web App (Model-View-Controller)
-	ASP.NET Core Web API
-	ASP.NET Core Web App (Razor Pages)
-	Blazor Server App
-	Blazor WebAssembly App&lt;/p&gt;
&lt;p&gt;## Advisory FAQ&lt;/p&gt;
&lt;p&gt;### How do I know if I am affected?&lt;/p&gt;
&lt;p&gt;If you are you using project templates listed in affected software, you may be exposed to the vulnerability.&lt;/p&gt;
&lt;p&gt;### How do I fix the issue?&lt;/p&gt;
&lt;p&gt;#### For existing projects:
If you ever created any of these projects via the dotnet new command or via Visual Studio&amp;#39;s File -&amp;gt; New Project gesture, and if you enabled federated authentication at project creation time, your project may be vulnerable. To remed…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: System.IdentityModel.Tokens.Jwt, NuGet: Microsoft.IdentityModel.JsonWebTokens&lt;/p&gt;
&lt;p&gt;A Denial of Service vulnerability exists in ASP.NET Core project templates which utilize JWT-based authentication tokens. This vulnerability allows an unauthenticated client to consume arbitrarily large amounts of server memory, potentially triggering an out-of-memory condition on the server and making the server no longer able to respond to legitimate requests.&lt;/p&gt;
&lt;p&gt;## Announcement&lt;/p&gt;
&lt;p&gt;Announcement for this issue can be found at  https://github.com/dotnet/announcements/issues/290&lt;/p&gt;
&lt;p&gt;### Mitigation factors&lt;/p&gt;
&lt;p&gt;This impacts only .NET Core-based projects that were created using any version of project templates listed in affected software. 
Other project templates e.g., console applications, MAUI applications, Windows Forms or WPF applications, are not affected.&lt;/p&gt;
&lt;p&gt;## Affected software&lt;/p&gt;
&lt;p&gt;This impacts only .NET Core-based projects that were created using any version of the below project templates.&lt;/p&gt;
&lt;p&gt;-	ASP.NET Core Web App (Model-View-Controller)
-	ASP.NET Core Web API
-	ASP.NET Core Web App (Razor Pages)
-	Blazor Server App
-	Blazor WebAssembly App&lt;/p&gt;
&lt;p&gt;## Advisory FAQ&lt;/p&gt;
&lt;p&gt;### How do I know if I am affected?&lt;/p&gt;
&lt;p&gt;If you are you using project templates listed in affected software, you may be exposed to the vulnerability.&lt;/p&gt;
&lt;p&gt;### How do I fix the issue?&lt;/p&gt;
&lt;p&gt;#### For existing projects:
If you ever created any of these projects via the dotnet new command or via Visual Studio&amp;#39;s File -&amp;gt; New Project gesture, and if you enabled federated authentication at project creation time, your project may be vulnerable. To remed…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-59j7-ghrg-fj52</guid>
    </item>
    <item>
      <title>gsd-2024-21319</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-21319</link>
      <description>gsd-2024-21319</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-21319</guid>
    </item>
    <item>
      <title>ICSA-25-100-02 — Siemens SIDIS Prime</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-100-02</link>
      <description>&lt;p&gt;Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn&amp;#39;t otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don&amp;#39;t have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions. Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn&amp;#39;t otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don&amp;#39;t have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions. Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-100-02</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-21319 — Microsoft Identity Denial of service vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-21319</link>
      <description>msrc_CVE-2024-21319</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-21319</guid>
    </item>
    <item>
      <title>RHSA-2024:0150 — Red Hat Security Advisory: .NET 8.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0150</link>
      <description>&lt;p&gt;dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0150</guid>
    </item>
    <item>
      <title>RHSA-2024:0255 — Red Hat Security Advisory: .NET 6.0 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0255</link>
      <description>&lt;p&gt;dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: Information Disclosure: MD.SqlClient(MDS) &amp;amp; System.data.SQLClient (SDS) dotnet: X509 Certificates - Validation Bypass across Azure dotnet: .NET Denial of Service Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0255</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-21319</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21319</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7&lt;/p&gt;
&lt;p&gt;Microsoft Identity Denial of service vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7&lt;/p&gt;
&lt;p&gt;Microsoft Identity Denial of service vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21319</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0039 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0039</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Microsoft Developer Tools ausnutzen, um seine Privilegien zu erhöhen, einen Denial of Service Zustand hervorzurufen oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Microsoft Developer Tools ausnutzen, um seine Privilegien zu erhöhen, einen Denial of Service Zustand hervorzurufen oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0039</guid>
    </item>
  </channel>
</rss>
