<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 19:43:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-161164</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-161164</link>
      <description>EUVD-2026-161164</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-161164</guid>
    </item>
    <item>
      <title>fkie_cve-2024-31209</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-31209</link>
      <description>&lt;p&gt;oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling `oidcc_provider_configuration_worker:get_provider_configuration/1` or `oidcc_provider_configuration_worker:get_jwks/1`. This issue has been patched in version(s)`3.1.2` &amp;amp; `3.2.0-beta.3`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling `oidcc_provider_configuration_worker:get_provider_configuration/1` or `oidcc_provider_configuration_worker:get_jwks/1`. This issue has been patched in version(s)`3.1.2` &amp;amp; `3.2.0-beta.3`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-31209</guid>
    </item>
    <item>
      <title>GHSA-mj35-2rgf-cv8p — OpenID Connect client Atom Exhaustion in provider configuration worker ets table location</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mj35-2rgf-cv8p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: oidcc&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;DOS by Atom exhaustion is possible by calling `oidcc_provider_configuration_worker:get_provider_configuration/1` or `oidcc_provider_configuration_worker:get_jwks/1`.&lt;/p&gt;
&lt;p&gt;Since the name is usually provided as a static value in the application using `oidcc`, this is unlikely to be exploited.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Example to illustrate the vulnerability.&lt;/p&gt;
&lt;p&gt;```erlang
{ok, Claims} =
  oidcc:retrieve_userinfo(
    Token,
    myapp_oidcc_config_provider,
    &amp;lt;&amp;lt;&amp;#34;client_id&amp;#34;&amp;gt;&amp;gt;,
    &amp;lt;&amp;lt;&amp;#34;client_secret&amp;#34;&amp;gt;&amp;gt;,
    #{}
  )
```&lt;/p&gt;
&lt;p&gt;The vulnerability is present in `oidcc_provider_configuration_worker:get_ets_table_name/1`.
The function `get_ets_table_name` is calling `erlang:list_to_atom/1`.&lt;/p&gt;
&lt;p&gt;https://github.com/erlef/oidcc/blob/018dbb53dd752cb1e331637d8e0e6a489ba1fae9/src/oidcc_provider_configuration_worker.erl#L385-L388&lt;/p&gt;
&lt;p&gt;There might be a case (Very highly improbable) where the 2nd argument of
`oidcc_provider_configuration_worker:get_*/1` is called with a different atom each time which eventually leads to
the atom table filling up and the node crashing.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patched in `3.0.2`, `3.1.2` &amp;amp; `3.2.0-beta.3`&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Make sure only valid provider configuration worker names are passed to the functions.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://erlef.github.io/security-wg/secure_coding_and_deployment_hardening/atom_exhaustion.html
* https://www.cve.org/CVERecord?id=CVE-2024-31209
* https://euvd.enisa.europa.eu/enisa/EUVD-2024-1249
* https://github.com/advisories/GHSA-mj35-2rgf-cv8p&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: oidcc&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;DOS by Atom exhaustion is possible by calling `oidcc_provider_configuration_worker:get_provider_configuration/1` or `oidcc_provider_configuration_worker:get_jwks/1`.&lt;/p&gt;
&lt;p&gt;Since the name is usually provided as a static value in the application using `oidcc`, this is unlikely to be exploited.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Example to illustrate the vulnerability.&lt;/p&gt;
&lt;p&gt;```erlang
{ok, Claims} =
  oidcc:retrieve_userinfo(
    Token,
    myapp_oidcc_config_provider,
    &amp;lt;&amp;lt;&amp;#34;client_id&amp;#34;&amp;gt;&amp;gt;,
    &amp;lt;&amp;lt;&amp;#34;client_secret&amp;#34;&amp;gt;&amp;gt;,
    #{}
  )
```&lt;/p&gt;
&lt;p&gt;The vulnerability is present in `oidcc_provider_configuration_worker:get_ets_table_name/1`.
The function `get_ets_table_name` is calling `erlang:list_to_atom/1`.&lt;/p&gt;
&lt;p&gt;https://github.com/erlef/oidcc/blob/018dbb53dd752cb1e331637d8e0e6a489ba1fae9/src/oidcc_provider_configuration_worker.erl#L385-L388&lt;/p&gt;
&lt;p&gt;There might be a case (Very highly improbable) where the 2nd argument of
`oidcc_provider_configuration_worker:get_*/1` is called with a different atom each time which eventually leads to
the atom table filling up and the node crashing.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patched in `3.0.2`, `3.1.2` &amp;amp; `3.2.0-beta.3`&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Make sure only valid provider configuration worker names are passed to the functions.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://erlef.github.io/security-wg/secure_coding_and_deployment_hardening/atom_exhaustion.html
* https://www.cve.org/CVERecord?id=CVE-2024-31209
* https://euvd.enisa.europa.eu/enisa/EUVD-2024-1249
* https://github.com/advisories/GHSA-mj35-2rgf-cv8p&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mj35-2rgf-cv8p</guid>
    </item>
    <item>
      <title>gsd-2024-31209</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-31209</link>
      <description>gsd-2024-31209</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-31209</guid>
    </item>
  </channel>
</rss>
