<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:54:57 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:3826 — Moderate: podman security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:3826</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: podman, AlmaLinux:9: podman-docker, AlmaLinux:9: podman-plugins, AlmaLinux:9: podman-remote, AlmaLinux:9: podman-tests&lt;/p&gt;
&lt;p&gt;The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.&lt;/p&gt;
&lt;p&gt;Security Fixes:&lt;/p&gt;
&lt;p&gt;* podman: jose-go: improper handling of highly compressed data (CVE-2024-28180)
* podman: golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)
* podman: jose: resource exhaustion (CVE-2024-28176)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: podman, AlmaLinux:9: podman-docker, AlmaLinux:9: podman-plugins, AlmaLinux:9: podman-remote, AlmaLinux:9: podman-tests&lt;/p&gt;
&lt;p&gt;The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.&lt;/p&gt;
&lt;p&gt;Security Fixes:&lt;/p&gt;
&lt;p&gt;* podman: jose-go: improper handling of highly compressed data (CVE-2024-28180)
* podman: golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)
* podman: jose: resource exhaustion (CVE-2024-28176)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:3826</guid>
    </item>
    <item>
      <title>bdu:2024-01954</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01954</link>
      <description>bdu:2024-01954</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01954</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0579 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</link>
      <description>certfr-2024-avi-0579</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</guid>
    </item>
    <item>
      <title>EUVD-2026-217365</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217365</link>
      <description>EUVD-2026-217365</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217365</guid>
    </item>
    <item>
      <title>fkie_cve-2024-28176</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-28176</link>
      <description>&lt;p&gt;jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has 
 been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user&amp;#39;s environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has 
 been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user&amp;#39;s environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-28176</guid>
    </item>
    <item>
      <title>GHSA-hhhv-q57g-882q — jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hhhv-q57g-882q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jose, npm: jose-node-cjs-runtime, npm: jose-node-esm-runtime&lt;/p&gt;
&lt;p&gt;A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the [support for decompressing plaintext after its decryption](https://www.rfc-editor.org/rfc/rfc7516.html#section-4.1.3). This allows an adversary to exploit specific scenarios where the compression ratio becomes exceptionally high. As a result, the length of the JWE token, which is determined by the compressed content&amp;#39;s size, can land below application-defined limits. In such cases, other existing application level mechanisms for preventing resource exhaustion may be rendered ineffective.&lt;/p&gt;
&lt;p&gt;Note that as per [RFC 8725](https://www.rfc-editor.org/rfc/rfc8725.html#name-avoid-compression-of-encryp) compression of data SHOULD NOT be done before encryption, because such compressed data often reveals information about the plaintext. For this reason the v5.x major version of `jose` removed support for compressed payloads entirely and is therefore NOT affected by this advisory.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Under certain conditions it is possible to have the user&amp;#39;s environment consume unreasonable amount of CPU time or memory during JWE Decryption operations.&lt;/p&gt;
&lt;p&gt;### Affected users&lt;/p&gt;
&lt;p&gt;The impact is limited only to Node.js users utilizing the JWE decryption APIs to decrypt JWEs from untrusted sources.&lt;/p&gt;
&lt;p&gt;You are NOT affected if any of the following applies to you&lt;/p&gt;
&lt;p&gt;- Your code uses jose version v5.x where JWE Compression is not supported anymore
- Your code runs in an environment other than Nod…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jose, npm: jose-node-cjs-runtime, npm: jose-node-esm-runtime&lt;/p&gt;
&lt;p&gt;A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the [support for decompressing plaintext after its decryption](https://www.rfc-editor.org/rfc/rfc7516.html#section-4.1.3). This allows an adversary to exploit specific scenarios where the compression ratio becomes exceptionally high. As a result, the length of the JWE token, which is determined by the compressed content&amp;#39;s size, can land below application-defined limits. In such cases, other existing application level mechanisms for preventing resource exhaustion may be rendered ineffective.&lt;/p&gt;
&lt;p&gt;Note that as per [RFC 8725](https://www.rfc-editor.org/rfc/rfc8725.html#name-avoid-compression-of-encryp) compression of data SHOULD NOT be done before encryption, because such compressed data often reveals information about the plaintext. For this reason the v5.x major version of `jose` removed support for compressed payloads entirely and is therefore NOT affected by this advisory.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Under certain conditions it is possible to have the user&amp;#39;s environment consume unreasonable amount of CPU time or memory during JWE Decryption operations.&lt;/p&gt;
&lt;p&gt;### Affected users&lt;/p&gt;
&lt;p&gt;The impact is limited only to Node.js users utilizing the JWE decryption APIs to decrypt JWEs from untrusted sources.&lt;/p&gt;
&lt;p&gt;You are NOT affected if any of the following applies to you&lt;/p&gt;
&lt;p&gt;- Your code uses jose version v5.x where JWE Compression is not supported anymore
- Your code runs in an environment other than Nod…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hhhv-q57g-882q</guid>
    </item>
    <item>
      <title>gsd-2024-28176</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-28176</link>
      <description>gsd-2024-28176</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-28176</guid>
    </item>
    <item>
      <title>OESA-2025-1075 — podman security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1075</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.(CVE-2024-24785)&lt;/p&gt;
&lt;p&gt;jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has 
 been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user&amp;amp;apos;s environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.(CVE-2024-28176)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.(CVE-2024-24785)&lt;/p&gt;
&lt;p&gt;jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has 
 been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user&amp;amp;apos;s environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.(CVE-2024-28176)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1075</guid>
    </item>
    <item>
      <title>RHBA-2024:1775 — Red Hat Bug Fix Advisory: Multicluster Engine for Kubernetes 2.5.2 bug fixes and container updates</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:1775</link>
      <description>&lt;p&gt;sanitize-html: Information Exposure when used on the backend jose: resource exhaustion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sanitize-html: Information Exposure when used on the backend jose: resource exhaustion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:1775</guid>
    </item>
    <item>
      <title>RHSA-2024:3826 — Red Hat Security Advisory: podman security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3826</link>
      <description>&lt;p&gt;golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm jose: resource exhaustion jose-go: improper handling of highly compressed data&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm jose: resource exhaustion jose-go: improper handling of highly compressed data&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3826</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-28176</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28176</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-jose, Ubuntu:24.04:LTS: node-jose, Ubuntu:25.10: node-jose&lt;/p&gt;
&lt;p&gt;jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has  been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user&amp;#39;s environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-jose, Ubuntu:24.04:LTS: node-jose, Ubuntu:25.10: node-jose&lt;/p&gt;
&lt;p&gt;jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has  been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user&amp;#39;s environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28176</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0767 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0767</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0767</guid>
    </item>
  </channel>
</rss>
