<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:00:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02480</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02480</link>
      <description>bdu:2024-02480</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02480</guid>
    </item>
    <item>
      <title>EUVD-2026-4661</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-4661</link>
      <description>EUVD-2026-4661</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-4661</guid>
    </item>
    <item>
      <title>fkie_cve-2024-29893</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29893</link>
      <description>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically,  it&amp;#39;s possible to crash the repo server component through an out of memory error by pointing it to a malicious Helm registry. The loadRepoIndex() function in the ArgoCD&amp;#39;s helm package, does not limit the size nor time while fetching the data. It fetches it and creates a byte slice from the retrieved data in one go. If the registry is implemented to push data continuously, the repo server will keep allocating memory until it runs out of it. A patch for this vulnerability has been released in v2.10.3, v2.9.8, and v2.8.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically,  it&amp;#39;s possible to crash the repo server component through an out of memory error by pointing it to a malicious Helm registry. The loadRepoIndex() function in the ArgoCD&amp;#39;s helm package, does not limit the size nor time while fetching the data. It fetches it and creates a byte slice from the retrieved data in one go. If the registry is implemented to push data continuously, the repo server will keep allocating memory until it runs out of it. A patch for this vulnerability has been released in v2.10.3, v2.9.8, and v2.8.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-29893</guid>
    </item>
    <item>
      <title>GHSA-jhwx-mhww-rgc3 — ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jhwx-mhww-rgc3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v2&lt;/p&gt;
&lt;p&gt;### Impact
All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically,  it&amp;#39;s possible to crash the repo server component through an out of memory error by pointing it to a malicious Helm registry.
The loadRepoIndex() function in the ArgoCD&amp;#39;s helm package, does not limit the size nor time while fetching the data. It fetches it and creates a byte slice from the retrieved data in one go. If the registry is implemented to push data continuously, the repo server will keep allocating memory until it runs out of it.&lt;/p&gt;
&lt;p&gt;### Patches
A patch for this vulnerability has been released in the following Argo CD versions:&lt;/p&gt;
&lt;p&gt;v2.10.5
v2.9.10
v2.8.14&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;Open an issue in [the Argo CD issue tracker](https://github.com/argoproj/argo-cd/issues) or [discussions](https://github.com/argoproj/argo-cd/discussions)
Join us on [Slack](https://argoproj.github.io/community/join-slack) in channel #argo-cd&lt;/p&gt;
&lt;p&gt;### Credits
This vulnerability was found &amp;amp; reported by Jakub Ciolek&lt;/p&gt;
&lt;p&gt;The Argo team would like to thank these contributors for their responsible disclosure and constructive communications during the resolve of this issue&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v2&lt;/p&gt;
&lt;p&gt;### Impact
All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically,  it&amp;#39;s possible to crash the repo server component through an out of memory error by pointing it to a malicious Helm registry.
The loadRepoIndex() function in the ArgoCD&amp;#39;s helm package, does not limit the size nor time while fetching the data. It fetches it and creates a byte slice from the retrieved data in one go. If the registry is implemented to push data continuously, the repo server will keep allocating memory until it runs out of it.&lt;/p&gt;
&lt;p&gt;### Patches
A patch for this vulnerability has been released in the following Argo CD versions:&lt;/p&gt;
&lt;p&gt;v2.10.5
v2.9.10
v2.8.14&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;Open an issue in [the Argo CD issue tracker](https://github.com/argoproj/argo-cd/issues) or [discussions](https://github.com/argoproj/argo-cd/discussions)
Join us on [Slack](https://argoproj.github.io/community/join-slack) in channel #argo-cd&lt;/p&gt;
&lt;p&gt;### Credits
This vulnerability was found &amp;amp; reported by Jakub Ciolek&lt;/p&gt;
&lt;p&gt;The Argo team would like to thank these contributors for their responsible disclosure and constructive communications during the resolve of this issue&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jhwx-mhww-rgc3</guid>
    </item>
    <item>
      <title>gsd-2024-29893</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-29893</link>
      <description>gsd-2024-29893</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-29893</guid>
    </item>
    <item>
      <title>RHSA-2024:1697 — Red Hat Security Advisory: Errata Advisory for Red Hat OpenShift GitOps v1.11.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:1697</link>
      <description>&lt;p&gt;CD: Users with `create` but not `override` privileges can perform local sync argo-cd: Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss argo-cd: Denial of Service Due to Unsafe Array Modification in Multi-threaded Environment argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow argo-cd: uncontrolled memory allocation vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CD: Users with `create` but not `override` privileges can perform local sync argo-cd: Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss argo-cd: Denial of Service Due to Unsafe Array Modification in Multi-threaded Environment argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow argo-cd: uncontrolled memory allocation vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:1697</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0812 — Red Hat OpenShift: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0812</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen oder um Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen oder um Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0812</guid>
    </item>
  </channel>
</rss>
