<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:04:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-220233</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-220233</link>
      <description>EUVD-2026-220233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-220233</guid>
    </item>
    <item>
      <title>fkie_cve-2025-27421</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27421</link>
      <description>&lt;p&gt;Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in the Abacus server&amp;#39;s Server-Sent Events (SSE) implementation. The issue occurs when clients disconnect from the /stream endpoint, as the server fails to properly clean up resources and terminate associated goroutines. This leads to resource exhaustion where the server continues running but eventually stops accepting new SSE connections while maintaining high memory usage. The vulnerability specifically involves improper channel cleanup in the event handling mechanism, causing goroutines to remain blocked indefinitely. This vulnerability is fixed in 1.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in the Abacus server&amp;#39;s Server-Sent Events (SSE) implementation. The issue occurs when clients disconnect from the /stream endpoint, as the server fails to properly clean up resources and terminate associated goroutines. This leads to resource exhaustion where the server continues running but eventually stops accepting new SSE connections while maintaining high memory usage. The vulnerability specifically involves improper channel cleanup in the event handling mechanism, causing goroutines to remain blocked indefinitely. This vulnerability is fixed in 1.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-27421</guid>
    </item>
    <item>
      <title>GHSA-vh64-54px-qgf8 — Goroutine Leak in Abacus SSE Implementation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vh64-54px-qgf8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/jasonlovesdoggo/abacus&lt;/p&gt;
&lt;p&gt;## Goroutine Leak in Abacus SSE Implementation&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A critical goroutine leak vulnerability has been identified in the Abacus server&amp;#39;s Server-Sent Events (SSE) implementation. The issue occurs when clients disconnect from the `/stream` endpoint, as the server fails to properly clean up resources and terminate associated goroutines. This leads to resource exhaustion where the server continues running but eventually stops accepting new SSE connections while maintaining high memory usage. The vulnerability specifically involves improper channel cleanup in the event handling mechanism, causing goroutines to remain blocked indefinitely.&lt;/p&gt;
&lt;p&gt;### [POC](https://github.com/JasonLovesDoggo/abacus/blob/main/docs/bugs/GHSA-vh64-54px-qgf8/test.py)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This vulnerability affects all versions of Abacus prior to v1.4.0. The issue causes:&lt;/p&gt;
&lt;p&gt;- Permanent unresponsiveness of the `/stream` endpoint after prolonged use
- Memory growth that stabilizes at a high level but prevents proper functionality
- Selective denial of service affecting only SSE connections while other endpoints remain functional
- Accumulated orphaned goroutines that cannot be garbage collected
- High resource consumption under sustained client connection/disconnection patterns&lt;/p&gt;
&lt;p&gt;Systems running Abacus in production with client applications that frequently establish and terminate SSE connections are most vulnerable. The issue becomes particularly apparent in high-traffic environments or during connection stress te…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/jasonlovesdoggo/abacus&lt;/p&gt;
&lt;p&gt;## Goroutine Leak in Abacus SSE Implementation&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A critical goroutine leak vulnerability has been identified in the Abacus server&amp;#39;s Server-Sent Events (SSE) implementation. The issue occurs when clients disconnect from the `/stream` endpoint, as the server fails to properly clean up resources and terminate associated goroutines. This leads to resource exhaustion where the server continues running but eventually stops accepting new SSE connections while maintaining high memory usage. The vulnerability specifically involves improper channel cleanup in the event handling mechanism, causing goroutines to remain blocked indefinitely.&lt;/p&gt;
&lt;p&gt;### [POC](https://github.com/JasonLovesDoggo/abacus/blob/main/docs/bugs/GHSA-vh64-54px-qgf8/test.py)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This vulnerability affects all versions of Abacus prior to v1.4.0. The issue causes:&lt;/p&gt;
&lt;p&gt;- Permanent unresponsiveness of the `/stream` endpoint after prolonged use
- Memory growth that stabilizes at a high level but prevents proper functionality
- Selective denial of service affecting only SSE connections while other endpoints remain functional
- Accumulated orphaned goroutines that cannot be garbage collected
- High resource consumption under sustained client connection/disconnection patterns&lt;/p&gt;
&lt;p&gt;Systems running Abacus in production with client applications that frequently establish and terminate SSE connections are most vulnerable. The issue becomes particularly apparent in high-traffic environments or during connection stress te…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vh64-54px-qgf8</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14889-1 — govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14889-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14889-1</guid>
    </item>
  </channel>
</rss>
