<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:40:06 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-09848</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09848</link>
      <description>bdu:2025-09848</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09848</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AM39668 — yawkat LZ4 Java provides LZ4 compression for Java</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</guid>
    </item>
    <item>
      <title>EUVD-2026-260099</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260099</link>
      <description>EUVD-2026-260099</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260099</guid>
    </item>
    <item>
      <title>fkie_cve-2025-8671</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-8671</link>
      <description>&lt;p&gt;A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS).  By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS).  By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-8671</guid>
    </item>
    <item>
      <title>OESA-2025-2166 — lighttpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2166</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: lighttpd&lt;/p&gt;
&lt;p&gt;Secure, fast, compliant and very flexible web-server which has been optimized for high-performance environments. It has a very low memory footprint compared to other webservers and takes care of cpu-load. Its advanced feature-set (FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make it the perfect webserver-software for every server that is suffering load problems.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.(CVE-2025-8671)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: lighttpd&lt;/p&gt;
&lt;p&gt;Secure, fast, compliant and very flexible web-server which has been optimized for high-performance environments. It has a very low memory footprint compared to other webservers and takes care of cpu-load. Its advanced feature-set (FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make it the perfect webserver-software for every server that is suffering load problems.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.(CVE-2025-8671)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2166</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15448-1 — lighttpd-1.4.80-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15448-1</link>
      <description>&lt;p&gt;lighttpd-1.4.80-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lighttpd-1.4.80-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15448-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2025-0070 — Pingora MadeYouReset HTTP/2 vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2025-0070</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: pingora-core&lt;/p&gt;
&lt;p&gt;Pingora deployments using versions prior to 0.6.0 that include HTTP/2 server support may be affected by the vulnerability described in CVE-2025-8671. Under certain conditions, Pingora applications may allocate buffers before the HTTP/2 reset and resulting stream cancellation is processed by the server. Repeated resets can force excessive memory consumption and lead to denial-of-service.&lt;/p&gt;
&lt;p&gt;On affected versions, malicious clients could trigger unusually high memory consumption, which may result in service instability or process termination.&lt;/p&gt;
&lt;p&gt;This issue is addressed by ensuring Pingora uses patched versions of HTTP/2 dependencies that include reset-handling safeguards to release connection resources before excessive memory buildup. Users are requested to upgrade to versions &amp;gt;= 0.6.0, which incorporates the required fixes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: pingora-core&lt;/p&gt;
&lt;p&gt;Pingora deployments using versions prior to 0.6.0 that include HTTP/2 server support may be affected by the vulnerability described in CVE-2025-8671. Under certain conditions, Pingora applications may allocate buffers before the HTTP/2 reset and resulting stream cancellation is processed by the server. Repeated resets can force excessive memory consumption and lead to denial-of-service.&lt;/p&gt;
&lt;p&gt;On affected versions, malicious clients could trigger unusually high memory consumption, which may result in service instability or process termination.&lt;/p&gt;
&lt;p&gt;This issue is addressed by ensuring Pingora uses patched versions of HTTP/2 dependencies that include reset-handling safeguards to release connection resources before excessive memory buildup. Users are requested to upgrade to versions &amp;gt;= 0.6.0, which incorporates the required fixes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2025-0070</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20995-1 — Security update for dnsdist</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20995-1</link>
      <description>&lt;p&gt;Security update for dnsdist&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for dnsdist&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20995-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-8671</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8671</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: lighttpd, Ubuntu:14.04:LTS: varnish, Ubuntu:Pro:16.04:LTS: lighttpd, Ubuntu:Pro:16.04:LTS: varnish, Ubuntu:Pro:18.04:LTS: h2o, Ubuntu:Pro:18.04:LTS: lighttpd, Ubuntu:Pro:18.04:LTS: varnish, Ubuntu:Pro:20.04:LTS: h2o, Ubuntu:20.04:LTS: lighttpd, Ubuntu:Pro:20.04:LTS: varnish and 11 more&lt;/p&gt;
&lt;p&gt;A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS).  By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: lighttpd, Ubuntu:14.04:LTS: varnish, Ubuntu:Pro:16.04:LTS: lighttpd, Ubuntu:Pro:16.04:LTS: varnish, Ubuntu:Pro:18.04:LTS: h2o, Ubuntu:Pro:18.04:LTS: lighttpd, Ubuntu:Pro:18.04:LTS: varnish, Ubuntu:Pro:20.04:LTS: h2o, Ubuntu:20.04:LTS: lighttpd, Ubuntu:Pro:20.04:LTS: varnish and 11 more&lt;/p&gt;
&lt;p&gt;A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS).  By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8671</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1830 — http/2 Implementierungen: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1830</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiednen http/2 Implementierungen ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiednen http/2 Implementierungen ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1830</guid>
    </item>
  </channel>
</rss>
