<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:33:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326590</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326590</link>
      <description>EUVD-2026-326590</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326590</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47213</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47213</link>
      <description>&lt;p&gt;Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, Boxlite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, Boxlite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the Boxlite service. This issue has been patched via commit 28159fc.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, Boxlite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, Boxlite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the Boxlite service. This issue has been patched via commit 28159fc.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47213</guid>
    </item>
    <item>
      <title>GHSA-xjhv-pp2r-6f82 — BoxLite has a Timeout Bypass Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xjhv-pp2r-6f82</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: boxlite&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;BoxLite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. BoxLite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, BoxLite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, BoxLite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the BoxLite service.&lt;/p&gt;
&lt;p&gt;#### Details&lt;/p&gt;
&lt;p&gt;1. ExecRequest with timeout_ms arrives at Execution service&lt;/p&gt;
&lt;p&gt;**File:** `guest/src/service/exec/mod.rs` **Function:** `spawn_execution()` (line 315) **Code:**&lt;/p&gt;
&lt;p&gt;```rust
// Step 3: Start timeout watcher (if requested)
if req.timeout_ms &amp;gt; 0 {
    timeout::start_timeout_watcher(
        state,
        execution_id.clone(),
        std::time::Duration::from_millis(req.timeout_ms),
    );
}
```&lt;/p&gt;
&lt;p&gt;**Issue:** Any nonzero `timeout_ms` triggers the timeout watcher. The host expects this to kill the process after the specified duration.&lt;/p&gt;
&lt;p&gt;2. Timeout watcher sends SIGALRM instead of SIGKILL&lt;/p&gt;
&lt;p&gt;**File:** `guest/src/service/exec/timeout.rs` **Function:** `start_timeout_watcher()` (line 13) **Code:**&lt;/p&gt;
&lt;p&gt;```rust
pub(super) fn start_timeout_watcher(
    exec_state: ExecutionState,
    exec_id: String,
    timeout: Duration,
) {
    tokio::spawn(…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: boxlite&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;BoxLite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. BoxLite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, BoxLite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, BoxLite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the BoxLite service.&lt;/p&gt;
&lt;p&gt;#### Details&lt;/p&gt;
&lt;p&gt;1. ExecRequest with timeout_ms arrives at Execution service&lt;/p&gt;
&lt;p&gt;**File:** `guest/src/service/exec/mod.rs` **Function:** `spawn_execution()` (line 315) **Code:**&lt;/p&gt;
&lt;p&gt;```rust
// Step 3: Start timeout watcher (if requested)
if req.timeout_ms &amp;gt; 0 {
    timeout::start_timeout_watcher(
        state,
        execution_id.clone(),
        std::time::Duration::from_millis(req.timeout_ms),
    );
}
```&lt;/p&gt;
&lt;p&gt;**Issue:** Any nonzero `timeout_ms` triggers the timeout watcher. The host expects this to kill the process after the specified duration.&lt;/p&gt;
&lt;p&gt;2. Timeout watcher sends SIGALRM instead of SIGKILL&lt;/p&gt;
&lt;p&gt;**File:** `guest/src/service/exec/timeout.rs` **Function:** `start_timeout_watcher()` (line 13) **Code:**&lt;/p&gt;
&lt;p&gt;```rust
pub(super) fn start_timeout_watcher(
    exec_state: ExecutionState,
    exec_id: String,
    timeout: Duration,
) {
    tokio::spawn(…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xjhv-pp2r-6f82</guid>
    </item>
    <item>
      <title>PYSEC-2026-2400 — BoxLite has a Timeout Bypass Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2400</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: boxlite&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;BoxLite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. BoxLite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, BoxLite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, BoxLite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the BoxLite service.&lt;/p&gt;
&lt;p&gt;#### Details&lt;/p&gt;
&lt;p&gt;1. ExecRequest with timeout_ms arrives at Execution service&lt;/p&gt;
&lt;p&gt;**File:** `guest/src/service/exec/mod.rs` **Function:** `spawn_execution()` (line 315) **Code:**&lt;/p&gt;
&lt;p&gt;```rust
// Step 3: Start timeout watcher (if requested)
if req.timeout_ms &amp;gt; 0 {
    timeout::start_timeout_watcher(
        state,
        execution_id.clone(),
        std::time::Duration::from_millis(req.timeout_ms),
    );
}
```&lt;/p&gt;
&lt;p&gt;**Issue:** Any nonzero `timeout_ms` triggers the timeout watcher. The host expects this to kill the process after the specified duration.&lt;/p&gt;
&lt;p&gt;2. Timeout watcher sends SIGALRM instead of SIGKILL&lt;/p&gt;
&lt;p&gt;**File:** `guest/src/service/exec/timeout.rs` **Function:** `start_timeout_watcher()` (line 13) **Code:**&lt;/p&gt;
&lt;p&gt;```rust
pub(super) fn start_timeout_watcher(
    exec_state: ExecutionState,
    exec_id: String,
    timeout: Duration,
) {
    tokio::spawn(…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: boxlite&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;BoxLite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. BoxLite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, BoxLite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, BoxLite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the BoxLite service.&lt;/p&gt;
&lt;p&gt;#### Details&lt;/p&gt;
&lt;p&gt;1. ExecRequest with timeout_ms arrives at Execution service&lt;/p&gt;
&lt;p&gt;**File:** `guest/src/service/exec/mod.rs` **Function:** `spawn_execution()` (line 315) **Code:**&lt;/p&gt;
&lt;p&gt;```rust
// Step 3: Start timeout watcher (if requested)
if req.timeout_ms &amp;gt; 0 {
    timeout::start_timeout_watcher(
        state,
        execution_id.clone(),
        std::time::Duration::from_millis(req.timeout_ms),
    );
}
```&lt;/p&gt;
&lt;p&gt;**Issue:** Any nonzero `timeout_ms` triggers the timeout watcher. The host expects this to kill the process after the specified duration.&lt;/p&gt;
&lt;p&gt;2. Timeout watcher sends SIGALRM instead of SIGKILL&lt;/p&gt;
&lt;p&gt;**File:** `guest/src/service/exec/timeout.rs` **Function:** `start_timeout_watcher()` (line 13) **Code:**&lt;/p&gt;
&lt;p&gt;```rust
pub(super) fn start_timeout_watcher(
    exec_state: ExecutionState,
    exec_id: String,
    timeout: Duration,
) {
    tokio::spawn(…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2400</guid>
    </item>
  </channel>
</rss>
