<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:03:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-337243</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337243</link>
      <description>EUVD-2026-337243</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337243</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42294</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42294</link>
      <description>&lt;p&gt;Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, the Webhook Interceptor loads the entire request body into memory before authenticating the request or verifying its signature. This occurs on the /api/v1/events/ endpoint, which is publicly accessible (albeit intended for webhooks). An attacker can send a request with an extremely large body (e.g., multiple gigabytes), causing the Argo Server to allocate excessive memory, potentially leading to an Out-Of-Memory (OOM) crash and denial of service. This issue has been patched in versions 3.7.14 and 4.0.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, the Webhook Interceptor loads the entire request body into memory before authenticating the request or verifying its signature. This occurs on the /api/v1/events/ endpoint, which is publicly accessible (albeit intended for webhooks). An attacker can send a request with an extremely large body (e.g., multiple gigabytes), causing the Argo Server to allocate excessive memory, potentially leading to an Out-Of-Memory (OOM) crash and denial of service. This issue has been patched in versions 3.7.14 and 4.0.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42294</guid>
    </item>
    <item>
      <title>GHSA-jcc8-g2q4-9fxq — Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jcc8-g2q4-9fxq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-workflows/v3, Go: github.com/argoproj/argo-workflows/v4&lt;/p&gt;
&lt;p&gt;**Severity:** Medium
**Component:** Webhook Interceptor (`server/auth/webhook`)
**Vulnerability Type:** Denial of Service (DoS)&lt;/p&gt;
&lt;p&gt;## Description
The Webhook Interceptor loads the entire request body into memory before authenticating the request or verifying its signature. This occurs on the `/api/v1/events/` endpoint, which is publicly accessible (albeit intended for webhooks). An attacker can send a request with an extremely large body (e.g., multiple gigabytes), causing the Argo Server to allocate excessive memory, potentially leading to an Out-Of-Memory (OOM) crash and denial of service.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code
In `server/auth/webhook/interceptor.go`:
```go
func (i *WebhookInterceptor) addWebhookAuthorization(r *http.Request, kube kubernetes.Interface) error {
    // ... basic checks ...
    
    // Vulnerability: Reads entire body into memory unconditionally
    buf, _ := io.ReadAll(r.Body)
    defer func() { r.Body = io.NopCloser(bytes.NewBuffer(buf)) }()
    
    // ... subsequent logic finds correct service account and secret ...
    // ... verification happens later ...
}
```
The `io.ReadAll` call happens before the signature verification loop.&lt;/p&gt;
&lt;p&gt;## Impact
- **Service Availability:** An attacker can crash the Argo Server, disrupting workflow execution and API access for all users.&lt;/p&gt;
&lt;p&gt;## PoC (Conceptual)
1.  Target the webhook endpoint: `POST /api/v1/events/some-namespace`
2.  Send a `Content-Length: 1000000000` (1GB) header.
3.  Stream 1GB of random data.
4.  Monitor server…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-workflows/v3, Go: github.com/argoproj/argo-workflows/v4&lt;/p&gt;
&lt;p&gt;**Severity:** Medium
**Component:** Webhook Interceptor (`server/auth/webhook`)
**Vulnerability Type:** Denial of Service (DoS)&lt;/p&gt;
&lt;p&gt;## Description
The Webhook Interceptor loads the entire request body into memory before authenticating the request or verifying its signature. This occurs on the `/api/v1/events/` endpoint, which is publicly accessible (albeit intended for webhooks). An attacker can send a request with an extremely large body (e.g., multiple gigabytes), causing the Argo Server to allocate excessive memory, potentially leading to an Out-Of-Memory (OOM) crash and denial of service.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code
In `server/auth/webhook/interceptor.go`:
```go
func (i *WebhookInterceptor) addWebhookAuthorization(r *http.Request, kube kubernetes.Interface) error {
    // ... basic checks ...
    
    // Vulnerability: Reads entire body into memory unconditionally
    buf, _ := io.ReadAll(r.Body)
    defer func() { r.Body = io.NopCloser(bytes.NewBuffer(buf)) }()
    
    // ... subsequent logic finds correct service account and secret ...
    // ... verification happens later ...
}
```
The `io.ReadAll` call happens before the signature verification loop.&lt;/p&gt;
&lt;p&gt;## Impact
- **Service Availability:** An attacker can crash the Argo Server, disrupting workflow execution and API access for all users.&lt;/p&gt;
&lt;p&gt;## PoC (Conceptual)
1.  Target the webhook endpoint: `POST /api/v1/events/some-namespace`
2.  Send a `Content-Length: 1000000000` (1GB) header.
3.  Stream 1GB of random data.
4.  Monitor server…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jcc8-g2q4-9fxq</guid>
    </item>
    <item>
      <title>RHSA-2026:73987 — Red Hat Security Advisory: RHOAI 3.3.7 - Red Hat OpenShift AI</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:73987</link>
      <description>&lt;p&gt;golang: net/url: Memory exhaustion in query parameter parsing in net/url urllib3: urllib3 Streaming API improperly handles highly compressed data nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy keras: Keras: Arbitrary file write via path traversal in archive extraction utilities sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/url: Memory exhaustion in query parameter parsing in net/url urllib3: urllib3 Streaming API improperly handles highly compressed data nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy keras: Keras: Arbitrary file write via path traversal in archive extraction utilities sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:73987</guid>
    </item>
  </channel>
</rss>
