<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:39:17 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-07985</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07985</link>
      <description>bdu:2026-07985</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07985</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-ED59299 — Security fix for CVE-2026-21452 applied in: stargate 2.0.44-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ed59299</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the stargate package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the stargate package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ed59299</guid>
    </item>
    <item>
      <title>EUVD-2026-264832</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264832</link>
      <description>EUVD-2026-264832</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264832</guid>
    </item>
    <item>
      <title>fkie_cve-2026-21452</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-21452</link>
      <description>&lt;p&gt;MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared EXT payload length when materializing the extension data. When ExtensionValue.getData() is invoked, the library attempts to allocate a byte array of the declared length without enforcing any upper bound. A malicious .msgpack file of only a few bytes can therefore trigger unbounded heap allocation, resulting in JVM heap exhaustion, process termination, or service unavailability. This vulnerability is triggered during model loading / deserialization, making it a model format vulnerability suitable for remote exploitation. The vulnerability enables a remote denial-of-service attack against applications that deserialize untrusted .msgpack model files using MessagePack for Java. A specially crafted but syntactically valid .msgpack file containing an EXT32 object with an attacker-controlled, excessively large payload length can trigger unbounded memory allocation during deserialization. When the model file is loaded, the library trusts the declared length metadata and attempts to allocate a byte array of that size, leading to rapid heap exhaustion, excessive garbage collection, or immediate JVM termination with an OutOfMemoryError. The attack requires no malformed bytes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared EXT payload length when materializing the extension data. When ExtensionValue.getData() is invoked, the library attempts to allocate a byte array of the declared length without enforcing any upper bound. A malicious .msgpack file of only a few bytes can therefore trigger unbounded heap allocation, resulting in JVM heap exhaustion, process termination, or service unavailability. This vulnerability is triggered during model loading / deserialization, making it a model format vulnerability suitable for remote exploitation. The vulnerability enables a remote denial-of-service attack against applications that deserialize untrusted .msgpack model files using MessagePack for Java. A specially crafted but syntactically valid .msgpack file containing an EXT32 object with an attacker-controlled, excessively large payload length can trigger unbounded memory allocation during deserialization. When the model file is loaded, the library trusts the declared length metadata and attempts to allocate a byte array of that size, leading to rapid heap exhaustion, excessive garbage collection, or immediate JVM termination with an OutOfMemoryError. The attack requires no malformed bytes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-21452</guid>
    </item>
    <item>
      <title>GHSA-cw39-r4h6-8j3x — MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cw39-r4h6-8j3x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.msgpack:msgpack-core&lt;/p&gt;
&lt;p&gt;### Summary
Affected Components:
```
org.msgpack.core.MessageUnpacker.readPayload()
org.msgpack.core.MessageUnpacker.unpackValue()
org.msgpack.value.ExtensionValue.getData()
```
A denial-of-service vulnerability exists in MessagePack for Java when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared EXT payload length when materializing the extension data. When ExtensionValue.getData() is invoked, the library attempts to allocate a byte array of the declared length without enforcing any upper bound. A malicious .msgpack file of only a few bytes can therefore trigger unbounded heap allocation, resulting in JVM heap exhaustion, process termination, or service unavailability. This vulnerability is triggered during model loading / deserialization, making it a model format vulnerability suitable for remote exploitation.&lt;/p&gt;
&lt;p&gt;### PoC
```
import msgpack
import struct
import os&lt;/p&gt;
&lt;p&gt;OUTPUT_DIR = &amp;#34;bombs&amp;#34;
os.makedirs(OUTPUT_DIR, exist_ok=True)&lt;/p&gt;
&lt;p&gt;# EXT format: fixext / ext8 / ext16 / ext32
# ext32 allows attacker-controlled length (uint32)&lt;/p&gt;
&lt;p&gt;length = 1
step = 10_000_000&lt;/p&gt;
&lt;p&gt;while True:
    try:
        # EXT32: 0xC9 | length (4 bytes) | type (1 byte)
        header = b&amp;#39;\xC9&amp;#39; + struct.pack(&amp;#34;&amp;gt;I&amp;#34;, length) + b&amp;#39;\x01&amp;#39;
        payload = b&amp;#39;A&amp;#39;   # actual data tiny&lt;/p&gt;
&lt;p&gt;data = header + payload&lt;/p&gt;
&lt;p&gt;fname = f&amp;#34;{OUTPUT_DIR}/ext_length_{length}.msgpack&amp;#34;
        with open(fname,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.msgpack:msgpack-core&lt;/p&gt;
&lt;p&gt;### Summary
Affected Components:
```
org.msgpack.core.MessageUnpacker.readPayload()
org.msgpack.core.MessageUnpacker.unpackValue()
org.msgpack.value.ExtensionValue.getData()
```
A denial-of-service vulnerability exists in MessagePack for Java when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared EXT payload length when materializing the extension data. When ExtensionValue.getData() is invoked, the library attempts to allocate a byte array of the declared length without enforcing any upper bound. A malicious .msgpack file of only a few bytes can therefore trigger unbounded heap allocation, resulting in JVM heap exhaustion, process termination, or service unavailability. This vulnerability is triggered during model loading / deserialization, making it a model format vulnerability suitable for remote exploitation.&lt;/p&gt;
&lt;p&gt;### PoC
```
import msgpack
import struct
import os&lt;/p&gt;
&lt;p&gt;OUTPUT_DIR = &amp;#34;bombs&amp;#34;
os.makedirs(OUTPUT_DIR, exist_ok=True)&lt;/p&gt;
&lt;p&gt;# EXT format: fixext / ext8 / ext16 / ext32
# ext32 allows attacker-controlled length (uint32)&lt;/p&gt;
&lt;p&gt;length = 1
step = 10_000_000&lt;/p&gt;
&lt;p&gt;while True:
    try:
        # EXT32: 0xC9 | length (4 bytes) | type (1 byte)
        header = b&amp;#39;\xC9&amp;#39; + struct.pack(&amp;#34;&amp;gt;I&amp;#34;, length) + b&amp;#39;\x01&amp;#39;
        payload = b&amp;#39;A&amp;#39;   # actual data tiny&lt;/p&gt;
&lt;p&gt;data = header + payload&lt;/p&gt;
&lt;p&gt;fname = f&amp;#34;{OUTPUT_DIR}/ext_length_{length}.msgpack&amp;#34;
        with open(fname,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cw39-r4h6-8j3x</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-21452</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-21452</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: msgpack-java, Ubuntu:22.04:LTS: msgpack-java, Ubuntu:24.04:LTS: msgpack-java, Ubuntu:25.10: msgpack-java, Ubuntu:26.04:LTS: msgpack-java&lt;/p&gt;
&lt;p&gt;MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared EXT payload length when materializing the extension data. When ExtensionValue.getData() is invoked, the library attempts to allocate a byte array of the declared length without enforcing any upper bound. A malicious .msgpack file of only a few bytes can therefore trigger unbounded heap allocation, resulting in JVM heap exhaustion, process termination, or service unavailability. This vulnerability is triggered during model loading / deserialization, making it a model format vulnerability suitable for remote exploitation. The vulnerability enables a remote denial-of-service attack against applications that deserialize untrusted .msgpack model files using MessagePack for Java. A specially crafted but syntactically valid .msgpack file containing an EXT32 object with an attacker-controlled, excessively large payload length can trigger unbounded memory allocation during deserialization. When the model file is loaded, the library trusts the declared length metadata and attempts to allocate a byte array of that size, leading to rapid heap exhaustion, excessive garbage collection, or immediate JVM termination with an OutOfMemoryError. The attack requires no malformed bytes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: msgpack-java, Ubuntu:22.04:LTS: msgpack-java, Ubuntu:24.04:LTS: msgpack-java, Ubuntu:25.10: msgpack-java, Ubuntu:26.04:LTS: msgpack-java&lt;/p&gt;
&lt;p&gt;MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared EXT payload length when materializing the extension data. When ExtensionValue.getData() is invoked, the library attempts to allocate a byte array of the declared length without enforcing any upper bound. A malicious .msgpack file of only a few bytes can therefore trigger unbounded heap allocation, resulting in JVM heap exhaustion, process termination, or service unavailability. This vulnerability is triggered during model loading / deserialization, making it a model format vulnerability suitable for remote exploitation. The vulnerability enables a remote denial-of-service attack against applications that deserialize untrusted .msgpack model files using MessagePack for Java. A specially crafted but syntactically valid .msgpack file containing an EXT32 object with an attacker-controlled, excessively large payload length can trigger unbounded memory allocation during deserialization. When the model file is loaded, the library trusts the declared length metadata and attempts to allocate a byte array of that size, leading to rapid heap exhaustion, excessive garbage collection, or immediate JVM termination with an OutOfMemoryError. The attack requires no malformed bytes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-21452</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1194 — Oracle Communications: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1194</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1194</guid>
    </item>
  </channel>
</rss>
