<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:36:15 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-05114</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05114</link>
      <description>bdu:2024-05114</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05114</guid>
    </item>
    <item>
      <title>certfr-2024-avi-1061 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1061</link>
      <description>certfr-2024-avi-1061</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-1061</guid>
    </item>
    <item>
      <title>EUVD-2026-5661</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-5661</link>
      <description>EUVD-2026-5661</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-5661</guid>
    </item>
    <item>
      <title>fkie_cve-2024-36129</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-36129</link>
      <description>&lt;p&gt;The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue.  It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue.  It is also fixed in the confighttp module version 0.102.0 and configgrpc module version 0.102.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-36129</guid>
    </item>
    <item>
      <title>GHSA-c74f-6mfw-mm4v — Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c74f-6mfw-mm4v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/collector/config/confighttp, Go: go.opentelemetry.io/collector/config/configgrpc&lt;/p&gt;
&lt;p&gt;### Summary
An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption.&lt;/p&gt;
&lt;p&gt;### Details
The OpenTelemetry Collector handles compressed HTTP requests by recognizing the Content-Encoding header, rewriting the HTTP request body, and allowing subsequent handlers to process decompressed data. It supports the gzip, zstd, zlib, snappy, and deflate compression algorithms. A &amp;#34;zip bomb&amp;#34; or &amp;#34;decompression bomb&amp;#34; is a malicious archive designed to crash or disable the system reading it. Decompression of HTTP requests is typically not enabled by default in popular server solutions due to associated security risks. A malicious attacker could leverage this weakness to crash the collector by sending a small request that, when uncompressed by the server, results in excessive memory consumption.&lt;/p&gt;
&lt;p&gt;During proof-of-concept (PoC) testing, all supported compression algorithms could be abused, with zstd causing the most significant impact. Compressing 10GB of all-zero data reduced it to 329KB. Sending an HTTP request with this compressed data instantly consumed all available server memory (the testing server had 32GB), leading to an out-of-memory (OOM) kill of the collector application instance.&lt;/p&gt;
&lt;p&gt;The root cause for this issue can be found in the following code path:&lt;/p&gt;
&lt;p&gt;**Affected File:**
[https://github.com/open-telemetry/opentelemetry-collector/[...]confighttp/compression.go](https://github.com/open-telemetry/opentelemetry-collector/blo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/collector/config/confighttp, Go: go.opentelemetry.io/collector/config/configgrpc&lt;/p&gt;
&lt;p&gt;### Summary
An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption.&lt;/p&gt;
&lt;p&gt;### Details
The OpenTelemetry Collector handles compressed HTTP requests by recognizing the Content-Encoding header, rewriting the HTTP request body, and allowing subsequent handlers to process decompressed data. It supports the gzip, zstd, zlib, snappy, and deflate compression algorithms. A &amp;#34;zip bomb&amp;#34; or &amp;#34;decompression bomb&amp;#34; is a malicious archive designed to crash or disable the system reading it. Decompression of HTTP requests is typically not enabled by default in popular server solutions due to associated security risks. A malicious attacker could leverage this weakness to crash the collector by sending a small request that, when uncompressed by the server, results in excessive memory consumption.&lt;/p&gt;
&lt;p&gt;During proof-of-concept (PoC) testing, all supported compression algorithms could be abused, with zstd causing the most significant impact. Compressing 10GB of all-zero data reduced it to 329KB. Sending an HTTP request with this compressed data instantly consumed all available server memory (the testing server had 32GB), leading to an out-of-memory (OOM) kill of the collector application instance.&lt;/p&gt;
&lt;p&gt;The root cause for this issue can be found in the following code path:&lt;/p&gt;
&lt;p&gt;**Affected File:**
[https://github.com/open-telemetry/opentelemetry-collector/[...]confighttp/compression.go](https://github.com/open-telemetry/opentelemetry-collector/blo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c74f-6mfw-mm4v</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14439-1 — alloy-1.4.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14439-1</link>
      <description>&lt;p&gt;alloy-1.4.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;alloy-1.4.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14439-1</guid>
    </item>
    <item>
      <title>RHSA-2024:3943 — Red Hat Security Advisory: Red Hat OpenShift distributed tracing 3.2.1 operator containers security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3943</link>
      <description>&lt;p&gt;opentelemetry-collector: denial of service via specially crafted HTTP or gRPC request&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;opentelemetry-collector: denial of service via specially crafted HTTP or gRPC request&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3943</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1392 — Red Hat OpenShift: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1392</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1392</guid>
    </item>
  </channel>
</rss>
