<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:25:51 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:33515 — Important: ruby:3.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:33515</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-bundled-gems, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler and 20 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses (CVE-2026-42245)
  * ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)
  * net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-bundled-gems, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler and 20 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses (CVE-2026-42245)
  * ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)
  * net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:33515</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-42245</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-42245</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: ruby-net-imap, Alpaquita:stream: ruby-net-imap&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: ruby-net-imap, Alpaquita:stream: ruby-net-imap&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-42245</guid>
    </item>
    <item>
      <title>BREW-imap-backup-CVE-2026-42245 — net-imap has quadratic complexity when reading response literals</title>
      <link>https://cve.radiocsirt.org/vuln/brew-imap-backup-cve-2026-42245</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: imap-backup&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`Net::IMAP::ResponseReader` has quadratic time complexity when reading large responses containing many string literals.  A hostile server can send responses which are crafted to exhaust the client&amp;#39;s CPU for a denial of service attack.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;For each literal in a response, `ResponseReader` rescans the entire growing response buffer.  The regular expression that is used to scan the response buffer runs in linear time.  With many literals, this becomes O(n²) total work.  The regular expression should run in constant time: it is anchored to the end and only the last 23 bytes of the buffer are relevant.&lt;/p&gt;
&lt;p&gt;Because the algorithmic complexity is super-linear, this bypasses protection from `max_response_size`: a response can stay well below the default size limit while still causing very large CPU cost.&lt;/p&gt;
&lt;p&gt;`Net::IMAP::ResponseReader` runs continuously in the receiver thread until the connection closes.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This consumes disproportionate CPU time in the client&amp;#39;s receiver thread.  A hostile server could use this to exhaust the client&amp;#39;s CPU for a denial of service attack.&lt;/p&gt;
&lt;p&gt;For a response near the default `max_response_size`, each individual regexp scan could take between 100 to 200ms on common modern hardware, and this may be repeated 200k times per megabyte of response.  While the regexp is scanning, it retains the Global VM lock, preventing other threads from running.&lt;/p&gt;
&lt;p&gt;Although other threads should not be _completely_ blocked, their run time will be signific…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: imap-backup&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`Net::IMAP::ResponseReader` has quadratic time complexity when reading large responses containing many string literals.  A hostile server can send responses which are crafted to exhaust the client&amp;#39;s CPU for a denial of service attack.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;For each literal in a response, `ResponseReader` rescans the entire growing response buffer.  The regular expression that is used to scan the response buffer runs in linear time.  With many literals, this becomes O(n²) total work.  The regular expression should run in constant time: it is anchored to the end and only the last 23 bytes of the buffer are relevant.&lt;/p&gt;
&lt;p&gt;Because the algorithmic complexity is super-linear, this bypasses protection from `max_response_size`: a response can stay well below the default size limit while still causing very large CPU cost.&lt;/p&gt;
&lt;p&gt;`Net::IMAP::ResponseReader` runs continuously in the receiver thread until the connection closes.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This consumes disproportionate CPU time in the client&amp;#39;s receiver thread.  A hostile server could use this to exhaust the client&amp;#39;s CPU for a denial of service attack.&lt;/p&gt;
&lt;p&gt;For a response near the default `max_response_size`, each individual regexp scan could take between 100 to 200ms on common modern hardware, and this may be repeated 200k times per megabyte of response.  While the regexp is scanning, it retains the Global VM lock, preventing other threads from running.&lt;/p&gt;
&lt;p&gt;Although other threads should not be _completely_ blocked, their run time will be signific…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-imap-backup-cve-2026-42245</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</link>
      <description>certfr-2026-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-GP85472 — Security fix for CVE-2026-42245 applied in: ruby-fluentd-1.19 1.19.2-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gp85472</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby-fluentd-1.19&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ruby-fluentd-1.19 package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby-fluentd-1.19&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ruby-fluentd-1.19 package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gp85472</guid>
    </item>
    <item>
      <title>EUVD-2026-317412</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-317412</link>
      <description>EUVD-2026-317412</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-317412</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42245</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42245</link>
      <description>&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client&amp;#39;s CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client&amp;#39;s CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42245</guid>
    </item>
    <item>
      <title>GHSA-q2mw-fvj9-vvcw — net-imap has quadratic complexity when reading response literals</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q2mw-fvj9-vvcw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: net-imap&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`Net::IMAP::ResponseReader` has quadratic time complexity when reading large responses containing many string literals.  A hostile server can send responses which are crafted to exhaust the client&amp;#39;s CPU for a denial of service attack.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;For each literal in a response, `ResponseReader` rescans the entire growing response buffer.  The regular expression that is used to scan the response buffer runs in linear time.  With many literals, this becomes O(n²) total work.  The regular expression should run in constant time: it is anchored to the end and only the last 23 bytes of the buffer are relevant.&lt;/p&gt;
&lt;p&gt;Because the algorithmic complexity is super-linear, this bypasses protection from `max_response_size`: a response can stay well below the default size limit while still causing very large CPU cost.&lt;/p&gt;
&lt;p&gt;`Net::IMAP::ResponseReader` runs continuously in the receiver thread until the connection closes.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This consumes disproportionate CPU time in the client&amp;#39;s receiver thread.  A hostile server could use this to exhaust the client&amp;#39;s CPU for a denial of service attack.&lt;/p&gt;
&lt;p&gt;For a response near the default `max_response_size`, each individual regexp scan could take between 100 to 200ms on common modern hardware, and this may be repeated 200k times per megabyte of response.  While the regexp is scanning, it retains the Global VM lock, preventing other threads from running.&lt;/p&gt;
&lt;p&gt;Although other threads should not be _completely_ blocked, their run time will be signific…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: net-imap&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`Net::IMAP::ResponseReader` has quadratic time complexity when reading large responses containing many string literals.  A hostile server can send responses which are crafted to exhaust the client&amp;#39;s CPU for a denial of service attack.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;For each literal in a response, `ResponseReader` rescans the entire growing response buffer.  The regular expression that is used to scan the response buffer runs in linear time.  With many literals, this becomes O(n²) total work.  The regular expression should run in constant time: it is anchored to the end and only the last 23 bytes of the buffer are relevant.&lt;/p&gt;
&lt;p&gt;Because the algorithmic complexity is super-linear, this bypasses protection from `max_response_size`: a response can stay well below the default size limit while still causing very large CPU cost.&lt;/p&gt;
&lt;p&gt;`Net::IMAP::ResponseReader` runs continuously in the receiver thread until the connection closes.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This consumes disproportionate CPU time in the client&amp;#39;s receiver thread.  A hostile server could use this to exhaust the client&amp;#39;s CPU for a denial of service attack.&lt;/p&gt;
&lt;p&gt;For a response near the default `max_response_size`, each individual regexp scan could take between 100 to 200ms on common modern hardware, and this may be repeated 200k times per megabyte of response.  While the regexp is scanning, it retains the Global VM lock, preventing other threads from running.&lt;/p&gt;
&lt;p&gt;Although other threads should not be _completely_ blocked, their run time will be signific…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q2mw-fvj9-vvcw</guid>
    </item>
    <item>
      <title>OESA-2026-2578 — ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2578</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: ruby, openEuler:22.03-LTS-SP4: ruby, openEuler:24.03-LTS-SP1: ruby, openEuler:24.03-LTS-SP3: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client&amp;amp;apos;s CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42245)&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return &amp;amp;quot;successfully&amp;amp;quot;, without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: ruby, openEuler:22.03-LTS-SP4: ruby, openEuler:24.03-LTS-SP1: ruby, openEuler:24.03-LTS-SP3: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client&amp;amp;apos;s CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42245)&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return &amp;amp;quot;successfully&amp;amp;quot;, without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2578</guid>
    </item>
    <item>
      <title>RHSA-2026:33515 — Red Hat Security Advisory: ruby:3.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33515</link>
      <description>&lt;p&gt;ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33515</guid>
    </item>
    <item>
      <title>RHSA-2026:33551 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33551</link>
      <description>&lt;p&gt;ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS ruby/net-imap: ruby: Net::IMAP: Denial of Service via large iteration count in SCRAM authentication net-imap: Net::IMAP: Command injection via non-synchronizing literals net-imap: rubygem-net-imap: Net::IMAP: Denial of Service via malformed command input net-imap: Net::IMAP: Arbitrary IMAP command injection due to improper input validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS ruby/net-imap: ruby: Net::IMAP: Denial of Service via large iteration count in SCRAM authentication net-imap: Net::IMAP: Command injection via non-synchronizing literals net-imap: rubygem-net-imap: Net::IMAP: Denial of Service via malformed command input net-imap: Net::IMAP: Arbitrary IMAP command injection due to improper input validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33551</guid>
    </item>
    <item>
      <title>RLSA-2026:33515 — Important: ruby:3.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:33515</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: ruby, Rocky Linux:8: rubygem-abrt, Rocky Linux:8: rubygem-mysql2, Rocky Linux:8: rubygem-pg&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses (CVE-2026-42245)&lt;/p&gt;
&lt;p&gt;* ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)&lt;/p&gt;
&lt;p&gt;* net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: ruby, Rocky Linux:8: rubygem-abrt, Rocky Linux:8: rubygem-mysql2, Rocky Linux:8: rubygem-pg&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses (CVE-2026-42245)&lt;/p&gt;
&lt;p&gt;* ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)&lt;/p&gt;
&lt;p&gt;* net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:33515</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-42245</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42245</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: jruby, Ubuntu:25.10: ruby3.3&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client&amp;#39;s CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: jruby, Ubuntu:25.10: ruby3.3&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client&amp;#39;s CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42245</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2117 — HCL BigFix Compliance (Ruby): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2117</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix Compliance ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix Compliance ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2117</guid>
    </item>
  </channel>
</rss>
