<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:34:51 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2024-7246</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-7246</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: grpc, Alpaquita:stream: grpc, BellSoft Hardened Containers:stream: grpc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: grpc, Alpaquita:stream: grpc, BellSoft Hardened Containers:stream: grpc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-7246</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0661 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0661</link>
      <description>certfr-2025-avi-0661</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0661</guid>
    </item>
    <item>
      <title>EUVD-2026-103115</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-103115</link>
      <description>EUVD-2026-103115</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-103115</guid>
    </item>
    <item>
      <title>fkie_cve-2024-7246</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-7246</link>
      <description>&lt;p&gt;It&amp;#39;s possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It&amp;#39;s also possible to use this vulnerability to leak other clients HTTP header keys, but not values.&lt;/p&gt;
&lt;p&gt;This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table.&lt;/p&gt;
&lt;p&gt;Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It&amp;#39;s possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It&amp;#39;s also possible to use this vulnerability to leak other clients HTTP header keys, but not values.&lt;/p&gt;
&lt;p&gt;This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table.&lt;/p&gt;
&lt;p&gt;Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-7246</guid>
    </item>
    <item>
      <title>GHSA-ghwg-gpp4-w4x3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ghwg-gpp4-w4x3</link>
      <description>&lt;p&gt;It&amp;#39;s possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It&amp;#39;s also possible to use this vulnerability to leak other clients HTTP header keys, but not values.&lt;/p&gt;
&lt;p&gt;This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table.&lt;/p&gt;
&lt;p&gt;Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It&amp;#39;s possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It&amp;#39;s also possible to use this vulnerability to leak other clients HTTP header keys, but not values.&lt;/p&gt;
&lt;p&gt;This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table.&lt;/p&gt;
&lt;p&gt;Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ghwg-gpp4-w4x3</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-7246 — HPACK table poisoning in gRPC C++, Python &amp; Ruby</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-7246</link>
      <description>msrc_CVE-2024-7246</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-7246</guid>
    </item>
    <item>
      <title>OESA-2024-2064 — grpc security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2064</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: grpc&lt;/p&gt;
&lt;p&gt;gRPC is a modern open source high performance RPC framework that can run in any environment. It can efficiently connect services in and across data centers with pluggable support for load balancing, tracing, health checking and authentication. It is also applicable in last mile of distributed computing to connect devices, mobile applications and browsers to backend services.&#13;
&#13;
Security Fix(es):&#13;
&#13;
It&amp;amp;apos;s possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It&amp;amp;apos;s also possible to use this vulnerability to leak other clients HTTP header keys, but not values.&#13;
&#13;
This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table.&#13;
&#13;
Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.(CVE-2024-7246)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: grpc&lt;/p&gt;
&lt;p&gt;gRPC is a modern open source high performance RPC framework that can run in any environment. It can efficiently connect services in and across data centers with pluggable support for load balancing, tracing, health checking and authentication. It is also applicable in last mile of distributed computing to connect devices, mobile applications and browsers to backend services.&#13;
&#13;
Security Fix(es):&#13;
&#13;
It&amp;amp;apos;s possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It&amp;amp;apos;s also possible to use this vulnerability to leak other clients HTTP header keys, but not values.&#13;
&#13;
This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table.&#13;
&#13;
Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.(CVE-2024-7246)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2064</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15031-1 — python311-grpcio-1.69.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15031-1</link>
      <description>&lt;p&gt;python311-grpcio-1.69.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-grpcio-1.69.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15031-1</guid>
    </item>
    <item>
      <title>RHSA-2024:6428 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6428</link>
      <description>&lt;p&gt;github.com/jaraco/zipp: Denial of Service (infinite loop) via crafted zip file in jaraco/zipp automation-controller: Gain access to the k8s API server via job execution with Container Group grpc: client communicating with a HTTP/2 proxy can poison the HPACK table between the proxy and the backend python-social-auth: Improper Handling of Case Sensitivity in social-auth-app-django python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats python-django: Potential denial-of-service in django.utils.html.urlize() python-django: Username enumeration through timing difference for users with unusable passwords python-django: Potential directory-traversal in django.core.files.storage.Storage.save() python-django: Potential denial-of-service in django.utils.translation.get_supported_language_variant() python-django: Memory exhaustion in django.utils.numberformat.floatformat() python-django: Potential denial-of-service vulnerability in django.utils.html.urlize() python-django: Potential denial-of-service vulnerability in django.utils.html.urlize() and AdminURLFieldWidget python-django: Potential SQL injection in QuerySet.values() and values_list()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/jaraco/zipp: Denial of Service (infinite loop) via crafted zip file in jaraco/zipp automation-controller: Gain access to the k8s API server via job execution with Container Group grpc: client communicating with a HTTP/2 proxy can poison the HPACK table between the proxy and the backend python-social-auth: Improper Handling of Case Sensitivity in social-auth-app-django python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats python-django: Potential denial-of-service in django.utils.html.urlize() python-django: Username enumeration through timing difference for users with unusable passwords python-django: Potential directory-traversal in django.core.files.storage.Storage.save() python-django: Potential denial-of-service in django.utils.translation.get_supported_language_variant() python-django: Memory exhaustion in django.utils.numberformat.floatformat() python-django: Potential denial-of-service vulnerability in django.utils.html.urlize() python-django: Potential denial-of-service vulnerability in django.utils.html.urlize() and AdminURLFieldWidget python-django: Potential SQL injection in QuerySet.values() and values_list()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6428</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:4393-1 — Security update for python-grpcio</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:4393-1</link>
      <description>&lt;p&gt;Security update for python-grpcio&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-grpcio&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:4393-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-7246</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-7246</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grpc, Ubuntu:18.04:LTS: grpc, Ubuntu:20.04:LTS: grpc, Ubuntu:22.04:LTS: grpc, Ubuntu:24.04:LTS: grpc, Ubuntu:25.10: grpc, Ubuntu:26.04:LTS: grpc&lt;/p&gt;
&lt;p&gt;It&amp;#39;s possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It&amp;#39;s also possible to use this vulnerability to leak other clients HTTP header keys, but not values. This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table. Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grpc, Ubuntu:18.04:LTS: grpc, Ubuntu:20.04:LTS: grpc, Ubuntu:22.04:LTS: grpc, Ubuntu:24.04:LTS: grpc, Ubuntu:25.10: grpc, Ubuntu:26.04:LTS: grpc&lt;/p&gt;
&lt;p&gt;It&amp;#39;s possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It&amp;#39;s also possible to use this vulnerability to leak other clients HTTP header keys, but not values. This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table. Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-7246</guid>
    </item>
  </channel>
</rss>
