<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:19:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-08314</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-08314</link>
      <description>bdu:2026-08314</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-08314</guid>
    </item>
    <item>
      <title>EUVD-2026-375484</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-375484</link>
      <description>EUVD-2026-375484</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-375484</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48853</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48853</link>
      <description>&lt;p&gt;Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server.&lt;/p&gt;
&lt;p&gt;&amp;#39;Elixir.GRPC.Codec.Erlpack&amp;#39;:decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process.&lt;/p&gt;
&lt;p&gt;This issue affects grpc: from 0.4.0 before 1.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server.&lt;/p&gt;
&lt;p&gt;&amp;#39;Elixir.GRPC.Codec.Erlpack&amp;#39;:decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process.&lt;/p&gt;
&lt;p&gt;This issue affects grpc: from 0.4.0 before 1.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48853</guid>
    </item>
    <item>
      <title>GHSA-grp7-v8xh-rj7h — gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-grp7-v8xh-rj7h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: grpc&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`GRPC.Codec.Erlpack.decode/2` calls `:erlang.binary_to_term/1` directly on the raw gRPC message body without the `:safe` option. Any unauthenticated peer that can reach a gRPC endpoint with `Content-Type: application/grpc+erlpack` can crash the entire BEAM node via atom table exhaustion or, if a decoded fun term flows into a call site that invokes it, achieve remote code execution inside the server process.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Root cause** — `lib/grpc/codec/erlpack.ex` implements `decode/2` as a bare `:erlang.binary_to_term(binary)` call with no `:safe` flag, no size limit, and no type validation. This has two independent exploitation paths:&lt;/p&gt;
&lt;p&gt;**1. DoS via atom exhaustion** — BEAM atoms are never garbage-collected and the global atom table is bounded (~1,048,576 entries). A crafted payload encoding large numbers of fresh atoms saturates the table and crashes the entire VM, taking down all applications on the node.&lt;/p&gt;
&lt;p&gt;**2. RCE via fun materialization** — Without `:safe`, `binary_to_term/1` reconstructs fun and external-fun terms from wire data. If the decoded value reaches any call site that applies it (e.g. `Enum.map`, `Task.async`, direct invocation), attacker-controlled code executes inside the server process.&lt;/p&gt;
&lt;p&gt;**Configuration requirement:** `GRPC.Codec.Erlpack` is not registered by default and must be explicitly added to the server&amp;#39;s `codecs` option.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Start a gRPC server with `codecs: [GRPC.Codec.Erlpack]`.
2. Open an HTTP/2 connection to the server.
3.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: grpc&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`GRPC.Codec.Erlpack.decode/2` calls `:erlang.binary_to_term/1` directly on the raw gRPC message body without the `:safe` option. Any unauthenticated peer that can reach a gRPC endpoint with `Content-Type: application/grpc+erlpack` can crash the entire BEAM node via atom table exhaustion or, if a decoded fun term flows into a call site that invokes it, achieve remote code execution inside the server process.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Root cause** — `lib/grpc/codec/erlpack.ex` implements `decode/2` as a bare `:erlang.binary_to_term(binary)` call with no `:safe` flag, no size limit, and no type validation. This has two independent exploitation paths:&lt;/p&gt;
&lt;p&gt;**1. DoS via atom exhaustion** — BEAM atoms are never garbage-collected and the global atom table is bounded (~1,048,576 entries). A crafted payload encoding large numbers of fresh atoms saturates the table and crashes the entire VM, taking down all applications on the node.&lt;/p&gt;
&lt;p&gt;**2. RCE via fun materialization** — Without `:safe`, `binary_to_term/1` reconstructs fun and external-fun terms from wire data. If the decoded value reaches any call site that applies it (e.g. `Enum.map`, `Task.async`, direct invocation), attacker-controlled code executes inside the server process.&lt;/p&gt;
&lt;p&gt;**Configuration requirement:** `GRPC.Codec.Erlpack` is not registered by default and must be explicitly added to the server&amp;#39;s `codecs` option.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Start a gRPC server with `codecs: [GRPC.Codec.Erlpack]`.
2. Open an HTTP/2 connection to the server.
3.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-grp7-v8xh-rj7h</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48853</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48853</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grpc, Ubuntu:18.04:LTS: grpc, Ubuntu:20.04:LTS: grpc, Ubuntu:22.04:LTS: grpc, Ubuntu:24.04:LTS: grpc, Ubuntu:25.10: grpc, Ubuntu:26.04:LTS: grpc&lt;/p&gt;
&lt;p&gt;Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server. &amp;#39;Elixir.GRPC.Codec.Erlpack&amp;#39;:decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process. This issue affects grpc: from 0.4.0 before 1.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grpc, Ubuntu:18.04:LTS: grpc, Ubuntu:20.04:LTS: grpc, Ubuntu:22.04:LTS: grpc, Ubuntu:24.04:LTS: grpc, Ubuntu:25.10: grpc, Ubuntu:26.04:LTS: grpc&lt;/p&gt;
&lt;p&gt;Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server. &amp;#39;Elixir.GRPC.Codec.Erlpack&amp;#39;:decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process. This issue affects grpc: from 0.4.0 before 1.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48853</guid>
    </item>
  </channel>
</rss>
