<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 11:28:22 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-KC30064 — Security fixes in akhq 0.27.1-r5</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-kc30064</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: akhq&lt;/p&gt;
&lt;p&gt;Package akhq version 0.27.1-r5 fixes 27 vulnerabilities: CVE-2026-58062, CVE-2026-59638, CVE-2026-59646, CVE-2026-12802, CVE-2026-59639...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: akhq&lt;/p&gt;
&lt;p&gt;Package akhq version 0.27.1-r5 fixes 27 vulnerabilities: CVE-2026-58062, CVE-2026-59638, CVE-2026-59646, CVE-2026-12802, CVE-2026-59639...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-kc30064</guid>
    </item>
    <item>
      <title>EUVD-2026-335498</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335498</link>
      <description>EUVD-2026-335498</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335498</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44241</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44241</link>
      <description>&lt;p&gt;Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, 3.10.6, and 3.8.14, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap&amp;lt;String, DateTimeFormatter&amp;gt; whose key is derived from the @Format annotation pattern concatenated with the locale from the HTTP Accept-Language header. Because Locale.forLanguageTag() accepts arbitrary BCP 47 private-use extensions (en-x-a001, en-x-a002, …), an unauthenticated attacker can generate an unlimited number of unique cache keys by sending requests with novel locale tags, growing the cache until heap memory is exhausted and the JVM crashes. This vulnerability is fixed in 4.10.22, 3.10.6, and 3.8.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, 3.10.6, and 3.8.14, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap&amp;lt;String, DateTimeFormatter&amp;gt; whose key is derived from the @Format annotation pattern concatenated with the locale from the HTTP Accept-Language header. Because Locale.forLanguageTag() accepts arbitrary BCP 47 private-use extensions (en-x-a001, en-x-a002, …), an unauthenticated attacker can generate an unlimited number of unique cache keys by sending requests with novel locale tags, growing the cache until heap memory is exhausted and the JVM crashes. This vulnerability is fixed in 4.10.22, 3.10.6, and 3.8.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44241</guid>
    </item>
    <item>
      <title>GHSA-8hjv-92q9-g4xj — Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Languag…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8hjv-92q9-g4xj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.micronaut:micronaut-context&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`TimeConverterRegistrar` caches `DateTimeFormatter` instances in an unbounded `ConcurrentHashMap&amp;lt;String, DateTimeFormatter&amp;gt;` whose key is derived from the `@Format` annotation pattern concatenated with the locale from the HTTP `Accept-Language` header. Because `Locale.forLanguageTag()` accepts arbitrary BCP 47 private-use extensions (`en-x-a001`, `en-x-a002`, …), an unauthenticated attacker can generate an unlimited number of unique cache keys by sending requests with novel locale tags, growing the cache until heap memory is exhausted and the JVM crashes. This is structurally identical to the recently patched GHSA-2hcp-gjrf-7fhc (`DefaultHtmlErrorResponseBodyProvider`), but `TimeConverterRegistrar.formattersCache` was not covered by that fix.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable cache is declared in `context/src/main/java/io/micronaut/runtime/converters/time/TimeConverterRegistrar.java` at line 123:&lt;/p&gt;
&lt;p&gt;```java
// TimeConverterRegistrar.java:123
private final Map&amp;lt;String, DateTimeFormatter&amp;gt; formattersCache = new ConcurrentHashMap&amp;lt;&amp;gt;();
```&lt;/p&gt;
&lt;p&gt;The `getFormatter` method at line 434 inserts into this map with no eviction or size limit:&lt;/p&gt;
&lt;p&gt;```java
// TimeConverterRegistrar.java:434-443
private DateTimeFormatter getFormatter(String pattern, ConversionContext context) {
    var key = pattern + context.getLocale();        // locale from Accept-Language header
    var cachedFormatter = formattersCache.get(key);
    if (cachedFormatter != null) {
        return cachedFormatter;
    }
    v…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.micronaut:micronaut-context&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`TimeConverterRegistrar` caches `DateTimeFormatter` instances in an unbounded `ConcurrentHashMap&amp;lt;String, DateTimeFormatter&amp;gt;` whose key is derived from the `@Format` annotation pattern concatenated with the locale from the HTTP `Accept-Language` header. Because `Locale.forLanguageTag()` accepts arbitrary BCP 47 private-use extensions (`en-x-a001`, `en-x-a002`, …), an unauthenticated attacker can generate an unlimited number of unique cache keys by sending requests with novel locale tags, growing the cache until heap memory is exhausted and the JVM crashes. This is structurally identical to the recently patched GHSA-2hcp-gjrf-7fhc (`DefaultHtmlErrorResponseBodyProvider`), but `TimeConverterRegistrar.formattersCache` was not covered by that fix.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable cache is declared in `context/src/main/java/io/micronaut/runtime/converters/time/TimeConverterRegistrar.java` at line 123:&lt;/p&gt;
&lt;p&gt;```java
// TimeConverterRegistrar.java:123
private final Map&amp;lt;String, DateTimeFormatter&amp;gt; formattersCache = new ConcurrentHashMap&amp;lt;&amp;gt;();
```&lt;/p&gt;
&lt;p&gt;The `getFormatter` method at line 434 inserts into this map with no eviction or size limit:&lt;/p&gt;
&lt;p&gt;```java
// TimeConverterRegistrar.java:434-443
private DateTimeFormatter getFormatter(String pattern, ConversionContext context) {
    var key = pattern + context.getLocale();        // locale from Accept-Language header
    var cachedFormatter = formattersCache.get(key);
    if (cachedFormatter != null) {
        return cachedFormatter;
    }
    v…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8hjv-92q9-g4xj</guid>
    </item>
  </channel>
</rss>
