<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:07:51 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-12933</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-12933</link>
      <description>bdu:2025-12933</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-12933</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0756 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</link>
      <description>certfr-2025-avi-0756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-LO22603 — Security fixes for CVE-2024-13009, CVE-2024-6763, CVE-2025-12383, CVE-2025-5115, CVE-2026-1225, CVE-2026-24281, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-lo22603</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: schema-registry&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the schema-registry package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: schema-registry&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the schema-registry package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-lo22603</guid>
    </item>
    <item>
      <title>EUVD-2026-259979</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259979</link>
      <description>EUVD-2026-259979</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259979</guid>
    </item>
    <item>
      <title>fkie_cve-2025-5115</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-5115</link>
      <description>&lt;p&gt;In Eclipse Jetty, versions &amp;lt;=9.4.57, &amp;lt;=10.0.25, &amp;lt;=11.0.25, &amp;lt;=12.0.21, &amp;lt;=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.&lt;/p&gt;
&lt;p&gt;For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal.
Per specification  https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame.
The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time.&lt;/p&gt;
&lt;p&gt;The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame.&lt;/p&gt;
&lt;p&gt;Links:&lt;/p&gt;
&lt;p&gt;*   https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Eclipse Jetty, versions &amp;lt;=9.4.57, &amp;lt;=10.0.25, &amp;lt;=11.0.25, &amp;lt;=12.0.21, &amp;lt;=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.&lt;/p&gt;
&lt;p&gt;For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal.
Per specification  https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame.
The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time.&lt;/p&gt;
&lt;p&gt;The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame.&lt;/p&gt;
&lt;p&gt;Links:&lt;/p&gt;
&lt;p&gt;*   https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-5115</guid>
    </item>
    <item>
      <title>GHSA-mmxm-8w33-wc4h — Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mmxm-8w33-wc4h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty.http2:http2-common, Maven: org.eclipse.jetty.http2:jetty-http2-common&lt;/p&gt;
&lt;p&gt;## Technical Details 
Below is a technical explanation of a newly discovered vulnerability in HTTP/2, which we refer to as “MadeYouReset.”&lt;/p&gt;
&lt;p&gt;### MadeYouReset Vulnerability Summary
The MadeYouReset DDoS vulnerability is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service.&lt;/p&gt;
&lt;p&gt;### Mechanism
The vulnerability uses malformed HTTP/2 control frames, or malformed flow, in order to make the server reset streams created by the client (using the RST_STREAM frame). 
The vulnerability could be triggered by several primitives, defined by the RFC of HTTP/2 (RFC 9113). The Primitives are:
1. WINDOW_UPDATE frame with an increment of 0 or an increment that makes the window exceed 2^31 - 1. (section 6.9 + 6.9.1)
2. HEADERS or DATA frames sent on a half-closed (remote) stream (which was closed using the END_STREAM flag). (note that for some implementations it&amp;#39;s possible a CONTINUATION frame to trigger that as well - but it&amp;#39;s very rare). (Section 5.1)
3. PRIORITY frame with a length other than 5. (section 6.3)
From our experience, the primitives are likely to exist in the decreasing order listed above.
Note that based on the implementation of the library, other primitives (which are not defined by the RFC) might exist - meaning scenarios in which RST_STREAM is not supposed to be sent, but in the implementation it does. On the other hand -…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty.http2:http2-common, Maven: org.eclipse.jetty.http2:jetty-http2-common&lt;/p&gt;
&lt;p&gt;## Technical Details 
Below is a technical explanation of a newly discovered vulnerability in HTTP/2, which we refer to as “MadeYouReset.”&lt;/p&gt;
&lt;p&gt;### MadeYouReset Vulnerability Summary
The MadeYouReset DDoS vulnerability is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service.&lt;/p&gt;
&lt;p&gt;### Mechanism
The vulnerability uses malformed HTTP/2 control frames, or malformed flow, in order to make the server reset streams created by the client (using the RST_STREAM frame). 
The vulnerability could be triggered by several primitives, defined by the RFC of HTTP/2 (RFC 9113). The Primitives are:
1. WINDOW_UPDATE frame with an increment of 0 or an increment that makes the window exceed 2^31 - 1. (section 6.9 + 6.9.1)
2. HEADERS or DATA frames sent on a half-closed (remote) stream (which was closed using the END_STREAM flag). (note that for some implementations it&amp;#39;s possible a CONTINUATION frame to trigger that as well - but it&amp;#39;s very rare). (Section 5.1)
3. PRIORITY frame with a length other than 5. (section 6.3)
From our experience, the primitives are likely to exist in the decreasing order listed above.
Note that based on the implementation of the library, other primitives (which are not defined by the RFC) might exist - meaning scenarios in which RST_STREAM is not supposed to be sent, but in the implementation it does. On the other hand -…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mmxm-8w33-wc4h</guid>
    </item>
    <item>
      <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</link>
      <description>NCSC-2026-0022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0022</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15482-1 — jetty-annotations-9.4.58-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15482-1</link>
      <description>&lt;p&gt;jetty-annotations-9.4.58-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jetty-annotations-9.4.58-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15482-1</guid>
    </item>
    <item>
      <title>RHSA-2025:16454 — Red Hat Security Advisory: Red Hat Product OCP Tools 4.19 OpenShift Jenkins security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:16454</link>
      <description>&lt;p&gt;jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to &amp;#34;MadeYouReset&amp;#34; DoS attack through HTTP/2 control frames&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to &amp;#34;MadeYouReset&amp;#34; DoS attack through HTTP/2 control frames&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:16454</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02993-2 — Security update for jetty-minimal</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02993-2</link>
      <description>&lt;p&gt;Security update for jetty-minimal&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jetty-minimal&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02993-2</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-5115</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5115</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: jetty, Ubuntu:16.04:LTS: jetty, Ubuntu:16.04:LTS: jetty9, Ubuntu:18.04:LTS: jetty9, Ubuntu:20.04:LTS: jetty9, Ubuntu:22.04:LTS: jetty9, Ubuntu:24.04:LTS: jetty9, Ubuntu:25.10: jetty9, Ubuntu:26.04:LTS: jetty9&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty, versions &amp;lt;=9.4.57, &amp;lt;=10.0.25, &amp;lt;=11.0.25, &amp;lt;=12.0.21, &amp;lt;=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory. For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame. The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time. The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame. Links:   * https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: jetty, Ubuntu:16.04:LTS: jetty, Ubuntu:16.04:LTS: jetty9, Ubuntu:18.04:LTS: jetty9, Ubuntu:20.04:LTS: jetty9, Ubuntu:22.04:LTS: jetty9, Ubuntu:24.04:LTS: jetty9, Ubuntu:25.10: jetty9, Ubuntu:26.04:LTS: jetty9&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty, versions &amp;lt;=9.4.57, &amp;lt;=10.0.25, &amp;lt;=11.0.25, &amp;lt;=12.0.21, &amp;lt;=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory. For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame. The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time. The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame. Links:   * https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5115</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1830 — http/2 Implementierungen: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1830</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiednen http/2 Implementierungen ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiednen http/2 Implementierungen ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1830</guid>
    </item>
  </channel>
</rss>
