<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:49:10 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0924 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0924</link>
      <description>certfr-2025-avi-0924</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0924</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AC01087 — During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cer…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ac01087</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: gitness&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the gitness package. During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: gitness&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the gitness package. During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ac01087</guid>
    </item>
    <item>
      <title>EUVD-2026-223705</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-223705</link>
      <description>EUVD-2026-223705</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-223705</guid>
    </item>
    <item>
      <title>fkie_cve-2025-30153</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-30153</link>
      <description>&lt;p&gt;kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-30153</guid>
    </item>
    <item>
      <title>GHSA-wq9g-9vfc-cfq9 — Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wq9g-9vfc-cfq9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/getkin/kin-openapi&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The root cause comes from the [ZipFileBodyDecoder](https://github.com/getkin/kin-openapi/blob/6da871e0e170b7637eb568c265c08bc2b5d6e7a3/openapi3filter/req_resp_decoder.go#L1523), which is registered [automatically](https://github.com/getkin/kin-openapi/blob/6da871e0e170b7637eb568c265c08bc2b5d6e7a3/openapi3filter/req_resp_decoder.go#L1275) by the module (contrary to what the [documentation says](https://github.com/getkin/kin-openapi?tab=readme-ov-file#custom-content-type-for-body-of-http-requestresponse).&lt;/p&gt;
&lt;p&gt;### PoC
To reproduce the vulnerability, you can use the following OpenAPI schema:
```yaml
openapi: 3.0.0
info:
  title: &amp;#39;Validator&amp;#39;
  version: 0.0.1
paths:
  /:
    post:
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              type: object
              required:
                - file
              properties:
                file:
                  type: string
                  format: binary
      responses:
        &amp;#39;200&amp;#39;:
          description: Created
```
And this code to validate the request (nothing fancy, it basically only calls the `openapi3filter.ValidateRequest` function`):
```go
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;fmt&amp;#34;
	&amp;#34;log&amp;#34;
	&amp;#34;net/http&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/getkin/kin-openap…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/getkin/kin-openapi&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The root cause comes from the [ZipFileBodyDecoder](https://github.com/getkin/kin-openapi/blob/6da871e0e170b7637eb568c265c08bc2b5d6e7a3/openapi3filter/req_resp_decoder.go#L1523), which is registered [automatically](https://github.com/getkin/kin-openapi/blob/6da871e0e170b7637eb568c265c08bc2b5d6e7a3/openapi3filter/req_resp_decoder.go#L1275) by the module (contrary to what the [documentation says](https://github.com/getkin/kin-openapi?tab=readme-ov-file#custom-content-type-for-body-of-http-requestresponse).&lt;/p&gt;
&lt;p&gt;### PoC
To reproduce the vulnerability, you can use the following OpenAPI schema:
```yaml
openapi: 3.0.0
info:
  title: &amp;#39;Validator&amp;#39;
  version: 0.0.1
paths:
  /:
    post:
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              type: object
              required:
                - file
              properties:
                file:
                  type: string
                  format: binary
      responses:
        &amp;#39;200&amp;#39;:
          description: Created
```
And this code to validate the request (nothing fancy, it basically only calls the `openapi3filter.ValidateRequest` function`):
```go
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;fmt&amp;#34;
	&amp;#34;log&amp;#34;
	&amp;#34;net/http&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/getkin/kin-openap…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wq9g-9vfc-cfq9</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14937-1 — govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14937-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14937-1</guid>
    </item>
    <item>
      <title>RHSA-2026:22689 — Red Hat Security Advisory: multicluster engine for Kubernetes v2.8.7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:22689</link>
      <description>&lt;p&gt;github.com/getkin/kin-openapi/openapi3filter: Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/getkin/kin-openapi/openapi3filter: Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:22689</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21756-1 — Security update for mcphost</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21756-1</link>
      <description>&lt;p&gt;Security update for mcphost&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for mcphost&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21756-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-30153</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-30153</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-getkin-kin-openapi, Ubuntu:24.04:LTS: golang-github-getkin-kin-openapi, Ubuntu:26.04:LTS: golang-github-getkin-kin-openapi&lt;/p&gt;
&lt;p&gt;kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-getkin-kin-openapi, Ubuntu:24.04:LTS: golang-github-getkin-kin-openapi, Ubuntu:26.04:LTS: golang-github-getkin-kin-openapi&lt;/p&gt;
&lt;p&gt;kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-30153</guid>
    </item>
  </channel>
</rss>
