<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 16:25:53 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-255163</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255163</link>
      <description>EUVD-2026-255163</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255163</guid>
    </item>
    <item>
      <title>fkie_cve-2025-62370</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-62370</link>
      <description>&lt;p&gt;Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered by malformed input to alloy_dyn_abi::TypedData could lead to a denial-of-service (DoS) via eip712_signing_hash(). Software with high availability requirements such as network services may be particularly impacted. If in use, external auto-restarting mechanisms can partially mitigate the availability issues unless repeated attacks are possible. The vulnerability was patched by adding a check to ensure the element is not empty before accessing its first element; an error is returned if it is empty. The fix is included in version v1.4.1 and backported to v0.8.26.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered by malformed input to alloy_dyn_abi::TypedData could lead to a denial-of-service (DoS) via eip712_signing_hash(). Software with high availability requirements such as network services may be particularly impacted. If in use, external auto-restarting mechanisms can partially mitigate the availability issues unless repeated attacks are possible. The vulnerability was patched by adding a check to ensure the element is not empty before accessing its first element; an error is returned if it is empty. The fix is included in version v1.4.1 and backported to v0.8.26.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-62370</guid>
    </item>
    <item>
      <title>GHSA-pgp9-98jm-wwq2 — alloy-dyn-abi has DoS vulnerability on `alloy_dyn_abi::TypedData` hashing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pgp9-98jm-wwq2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: alloy-dyn-abi&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An uncaught panic triggered by malformed input to `alloy_dyn_abi::TypedData` could lead to a denial-of-service (DoS) via `eip712_signing_hash()`.&lt;/p&gt;
&lt;p&gt;Software with high availability requirements such as network services may be particularly impacted. If in use, external auto-restarting mechanisms can partially mitigate the availability issues unless repeated attacks are possible.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The vulnerability was patched by adding a check to ensure the element is not empty before accessing its first element; an error is returned if it is empty. The fix is included in version [`v1.4.1`](https://crates.io/crates/alloy-dyn-abi/1.4.1) and backported to [`v0.8.26`](https://crates.io/crates/alloy-dyn-abi/0.8.26).&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;There is no known workaround that mitigates the vulnerability. Upgrading to a patched version is the recommended course of action.&lt;/p&gt;
&lt;p&gt;### Reported by&lt;/p&gt;
&lt;p&gt;Christian Reitter &amp;amp; Zeke Mostov from [Turnkey](https://www.turnkey.com/)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: alloy-dyn-abi&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An uncaught panic triggered by malformed input to `alloy_dyn_abi::TypedData` could lead to a denial-of-service (DoS) via `eip712_signing_hash()`.&lt;/p&gt;
&lt;p&gt;Software with high availability requirements such as network services may be particularly impacted. If in use, external auto-restarting mechanisms can partially mitigate the availability issues unless repeated attacks are possible.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The vulnerability was patched by adding a check to ensure the element is not empty before accessing its first element; an error is returned if it is empty. The fix is included in version [`v1.4.1`](https://crates.io/crates/alloy-dyn-abi/1.4.1) and backported to [`v0.8.26`](https://crates.io/crates/alloy-dyn-abi/0.8.26).&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;There is no known workaround that mitigates the vulnerability. Upgrading to a patched version is the recommended course of action.&lt;/p&gt;
&lt;p&gt;### Reported by&lt;/p&gt;
&lt;p&gt;Christian Reitter &amp;amp; Zeke Mostov from [Turnkey](https://www.turnkey.com/)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pgp9-98jm-wwq2</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15652-1 — cargo-audit-advisory-db-20251021-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15652-1</link>
      <description>&lt;p&gt;cargo-audit-advisory-db-20251021-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cargo-audit-advisory-db-20251021-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15652-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2025-0073 — DoS vulnerability on `alloy_dyn_abi::TypedData` hashing</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2025-0073</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: alloy-dyn-abi&lt;/p&gt;
&lt;p&gt;An uncaught panic triggered by malformed input to `alloy_dyn_abi::TypedData` could lead to a denial-of-service (DoS) via `eip712_signing_hash()`.&lt;/p&gt;
&lt;p&gt;Software with high availability requirements such as network services may be particularly impacted. If in use, external auto-restarting mechanisms can partially mitigate the availability issues unless repeated attacks are possible.&lt;/p&gt;
&lt;p&gt;The vulnerability was patched by adding a check to ensure the element is not empty before accessing its first element; an error is returned if it is empty. The fix is included in version [v1.4.1](https://crates.io/crates/alloy-dyn-abi/1.4.1) and backported to [v0.8.26](https://crates.io/crates/alloy-dyn-abi/0.8.26).&lt;/p&gt;
&lt;p&gt;There is no known workaround that mitigates the vulnerability. Upgrading to a patched version is the recommended course of action.&lt;/p&gt;
&lt;p&gt;Reported by [Christian Reitter](https://github.com/cr-tk) &amp;amp; [Zeke Mostov](https://github.com/emostov) from [Turnkey](https://www.turnkey.com/).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: alloy-dyn-abi&lt;/p&gt;
&lt;p&gt;An uncaught panic triggered by malformed input to `alloy_dyn_abi::TypedData` could lead to a denial-of-service (DoS) via `eip712_signing_hash()`.&lt;/p&gt;
&lt;p&gt;Software with high availability requirements such as network services may be particularly impacted. If in use, external auto-restarting mechanisms can partially mitigate the availability issues unless repeated attacks are possible.&lt;/p&gt;
&lt;p&gt;The vulnerability was patched by adding a check to ensure the element is not empty before accessing its first element; an error is returned if it is empty. The fix is included in version [v1.4.1](https://crates.io/crates/alloy-dyn-abi/1.4.1) and backported to [v0.8.26](https://crates.io/crates/alloy-dyn-abi/0.8.26).&lt;/p&gt;
&lt;p&gt;There is no known workaround that mitigates the vulnerability. Upgrading to a patched version is the recommended course of action.&lt;/p&gt;
&lt;p&gt;Reported by [Christian Reitter](https://github.com/cr-tk) &amp;amp; [Zeke Mostov](https://github.com/emostov) from [Turnkey](https://www.turnkey.com/).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2025-0073</guid>
    </item>
  </channel>
</rss>
