<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:50:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-10993</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10993</link>
      <description>bdu:2025-10993</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10993</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0754 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0754</link>
      <description>certfr-2025-avi-0754</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0754</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CL03013 — Netty is an asynchronous, event-driven network application framework</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cl03013</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-hive package. Netty is an asynchronous, event-driven network application framework. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-hive package. Netty is an asynchronous, event-driven network application framework. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cl03013</guid>
    </item>
    <item>
      <title>EUVD-2026-260033</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260033</link>
      <description>EUVD-2026-260033</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260033</guid>
    </item>
    <item>
      <title>fkie_cve-2025-55163</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55163</link>
      <description>&lt;p&gt;Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-55163</guid>
    </item>
    <item>
      <title>GHSA-prj3-ccx8-p6x4 — Netty affected by MadeYouReset HTTP/2 DDoS vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-prj3-ccx8-p6x4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http2, Maven: io.grpc:grpc-netty-shaded&lt;/p&gt;
&lt;p&gt;Below is a technical explanation of a newly discovered vulnerability in HTTP/2, which we refer to as “MadeYouReset.”&lt;/p&gt;
&lt;p&gt;### MadeYouReset Vulnerability Summary
The MadeYouReset DDoS vulnerability is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service.&lt;/p&gt;
&lt;p&gt;### Mechanism
The vulnerability uses malformed HTTP/2 control frames, or malformed flow, in order to make the server reset streams created by the client (using the RST_STREAM frame). 
The vulnerability could be triggered by several primitives, defined by the RFC of HTTP/2 (RFC 9113). The Primitives are:
1. WINDOW_UPDATE frame with an increment of 0 or an increment that makes the window exceed 2^31 - 1. (section 6.9 + 6.9.1)
2. HEADERS or DATA frames sent on a half-closed (remote) stream (which was closed using the END_STREAM flag). (note that for some implementations it&amp;#39;s possible a CONTINUATION frame to trigger that as well - but it&amp;#39;s very rare). (Section 5.1)
3. PRIORITY frame with a length other than 5. (section 6.3)
From our experience, the primitives are likely to exist in the decreasing order listed above.
Note that based on the implementation of the library, other primitives (which are not defined by the RFC) might exist - meaning scenarios in which RST_STREAM is not supposed to be sent, but in the implementation it does. On the other hand - some RFC-defined primi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http2, Maven: io.grpc:grpc-netty-shaded&lt;/p&gt;
&lt;p&gt;Below is a technical explanation of a newly discovered vulnerability in HTTP/2, which we refer to as “MadeYouReset.”&lt;/p&gt;
&lt;p&gt;### MadeYouReset Vulnerability Summary
The MadeYouReset DDoS vulnerability is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service.&lt;/p&gt;
&lt;p&gt;### Mechanism
The vulnerability uses malformed HTTP/2 control frames, or malformed flow, in order to make the server reset streams created by the client (using the RST_STREAM frame). 
The vulnerability could be triggered by several primitives, defined by the RFC of HTTP/2 (RFC 9113). The Primitives are:
1. WINDOW_UPDATE frame with an increment of 0 or an increment that makes the window exceed 2^31 - 1. (section 6.9 + 6.9.1)
2. HEADERS or DATA frames sent on a half-closed (remote) stream (which was closed using the END_STREAM flag). (note that for some implementations it&amp;#39;s possible a CONTINUATION frame to trigger that as well - but it&amp;#39;s very rare). (Section 5.1)
3. PRIORITY frame with a length other than 5. (section 6.3)
From our experience, the primitives are likely to exist in the decreasing order listed above.
Note that based on the implementation of the library, other primitives (which are not defined by the RFC) might exist - meaning scenarios in which RST_STREAM is not supposed to be sent, but in the implementation it does. On the other hand - some RFC-defined primi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-prj3-ccx8-p6x4</guid>
    </item>
    <item>
      <title>jvndb-2026-020740</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-020740</link>
      <description>&lt;p&gt;Hitachi Infrastructure Analytics Advisor contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer contains the following vulnerabilities:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer viewpoint contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Viewpoint contains the following vulnerabilities:&#13;
&#13;
CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, CVE-2025-58056, CVE-2025-58057&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hitachi Infrastructure Analytics Advisor contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer contains the following vulnerabilities:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer viewpoint contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Viewpoint contains the following vulnerabilities:&#13;
&#13;
CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, CVE-2025-58056, CVE-2025-58057&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-020740</guid>
    </item>
    <item>
      <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</link>
      <description>NCSC-2026-0022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0022</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15483-1 — netty-4.1.124-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15483-1</link>
      <description>&lt;p&gt;netty-4.1.124-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-4.1.124-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15483-1</guid>
    </item>
    <item>
      <title>RHSA-2025:14004 — Red Hat Security Advisory: Red Hat build of Quarkus 3.15.6.SP1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:14004</link>
      <description>&lt;p&gt;netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:14004</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03021-1 — Security update for netty</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03021-1</link>
      <description>&lt;p&gt;Security update for netty&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for netty&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03021-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-55163</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55163</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:24.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:25.10: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:24.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:25.10: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55163</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1830 — http/2 Implementierungen: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1830</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiednen http/2 Implementierungen ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiednen http/2 Implementierungen ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1830</guid>
    </item>
  </channel>
</rss>
