<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 11:44:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-08784</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-08784</link>
      <description>bdu:2026-08784</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-08784</guid>
    </item>
    <item>
      <title>BREW-krane-CVE-2026-54297 — Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters</title>
      <link>https://cve.radiocsirt.org/vuln/brew-krane-cve-2026-54297</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: krane&lt;/p&gt;
&lt;p&gt;`Faraday::NestedParamsEncoder`, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth.&lt;/p&gt;
&lt;p&gt;A crafted query string such as:&lt;/p&gt;
&lt;p&gt;```text
a[x][x][x][x]...[x]=1
```&lt;/p&gt;
&lt;p&gt;causes Faraday to build a deeply nested Ruby `Hash` structure. The internal `dehash` routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught `SystemStackError` (`stack level too deep`), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday&amp;#39;s nested query parsing or URL-building paths.&lt;/p&gt;
&lt;p&gt;This has been patched in version 2.14.3 and backported to 1.10.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: krane&lt;/p&gt;
&lt;p&gt;`Faraday::NestedParamsEncoder`, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth.&lt;/p&gt;
&lt;p&gt;A crafted query string such as:&lt;/p&gt;
&lt;p&gt;```text
a[x][x][x][x]...[x]=1
```&lt;/p&gt;
&lt;p&gt;causes Faraday to build a deeply nested Ruby `Hash` structure. The internal `dehash` routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught `SystemStackError` (`stack level too deep`), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday&amp;#39;s nested query parsing or URL-building paths.&lt;/p&gt;
&lt;p&gt;This has been patched in version 2.14.3 and backported to 1.10.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-krane-cve-2026-54297</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-DE16221 — Security fixes for CVE-2026-54171, CVE-2026-54297, CVE-2026-54522, CVE-2026-54904, CVE-2026-54905, CVE-2026-54906, ghsa…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-de16221</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby-fluentd-1.18&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the ruby-fluentd-1.18 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby-fluentd-1.18&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the ruby-fluentd-1.18 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-de16221</guid>
    </item>
    <item>
      <title>EUVD-2026-352408</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352408</link>
      <description>EUVD-2026-352408</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352408</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54297</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54297</link>
      <description>&lt;p&gt;Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday&amp;#39;s nested query parsing or URL-building paths. This vulnerability is fixed in 1.10.6 and 2.14.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday&amp;#39;s nested query parsing or URL-building paths. This vulnerability is fixed in 1.10.6 and 2.14.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54297</guid>
    </item>
    <item>
      <title>GHSA-98m9-hrrm-r99r — Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-98m9-hrrm-r99r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: faraday&lt;/p&gt;
&lt;p&gt;`Faraday::NestedParamsEncoder`, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth.&lt;/p&gt;
&lt;p&gt;A crafted query string such as:&lt;/p&gt;
&lt;p&gt;```text
a[x][x][x][x]...[x]=1
```&lt;/p&gt;
&lt;p&gt;causes Faraday to build a deeply nested Ruby `Hash` structure. The internal `dehash` routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught `SystemStackError` (`stack level too deep`), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday&amp;#39;s nested query parsing or URL-building paths.&lt;/p&gt;
&lt;p&gt;This has been patched in version 2.14.3 and backported to 1.10.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: faraday&lt;/p&gt;
&lt;p&gt;`Faraday::NestedParamsEncoder`, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth.&lt;/p&gt;
&lt;p&gt;A crafted query string such as:&lt;/p&gt;
&lt;p&gt;```text
a[x][x][x][x]...[x]=1
```&lt;/p&gt;
&lt;p&gt;causes Faraday to build a deeply nested Ruby `Hash` structure. The internal `dehash` routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught `SystemStackError` (`stack level too deep`), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday&amp;#39;s nested query parsing or URL-building paths.&lt;/p&gt;
&lt;p&gt;This has been patched in version 2.14.3 and backported to 1.10.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-98m9-hrrm-r99r</guid>
    </item>
    <item>
      <title>OESA-2026-2802 — rubygem-faraday security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2802</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: rubygem-faraday&lt;/p&gt;
&lt;p&gt;HTTP/REST API client library&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday&amp;amp;apos;s build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby&amp;amp;apos;s URI#merge to combine the connection&amp;amp;apos;s base URL with a user-supplied path. Per RFC 3986, protocol-relative URLs (e.g. //evil.com/path) are treated as network-path references that override the base URL&amp;amp;apos;s host/authority component. This means that if any application passes user-controlled input to Faraday&amp;amp;apos;s get(), post(), build_url(), or other request methods, an attacker can supply a protocol-relative URL like //attacker.com/endpoint to redirect the request to an arbitrary host, enabling Server-Side Request Forgery (SSRF). This vulnerability is fixed in 2.14.1.(CVE-2026-25765)&lt;/p&gt;
&lt;p&gt;Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: rubygem-faraday&lt;/p&gt;
&lt;p&gt;HTTP/REST API client library&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday&amp;amp;apos;s build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby&amp;amp;apos;s URI#merge to combine the connection&amp;amp;apos;s base URL with a user-supplied path. Per RFC 3986, protocol-relative URLs (e.g. //evil.com/path) are treated as network-path references that override the base URL&amp;amp;apos;s host/authority component. This means that if any application passes user-controlled input to Faraday&amp;amp;apos;s get(), post(), build_url(), or other request methods, an attacker can supply a protocol-relative URL like //attacker.com/endpoint to redirect the request to an arbitrary host, enabling Server-Side Request Forgery (SSRF). This vulnerability is fixed in 2.14.1.(CVE-2026-25765)&lt;/p&gt;
&lt;p&gt;Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2802</guid>
    </item>
    <item>
      <title>RHSA-2026:50221 — Red Hat Security Advisory: Satellite 6.19.3 Async Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:50221</link>
      <description>&lt;p&gt;org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing katello: missing repository authorization in content_uploads exposes cross-product content existence python-pillow: Pillow: Denial of Service via crafted PCF font data python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files faraday: Faraday: Denial of Service via crafted nested query strings python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file nokogiri: Nokogiri: Denial of Service or Information Disclosure via invalid encoding handling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing katello: missing repository authorization in content_uploads exposes cross-product content existence python-pillow: Pillow: Denial of Service via crafted PCF font data python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files faraday: Faraday: Denial of Service via crafted nested query strings python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file nokogiri: Nokogiri: Denial of Service or Information Disclosure via invalid encoding handling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:50221</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54297</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54297</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-faraday, Ubuntu:16.04:LTS: ruby-faraday, Ubuntu:18.04:LTS: ruby-faraday, Ubuntu:20.04:LTS: ruby-faraday, Ubuntu:22.04:LTS: ruby-faraday, Ubuntu:24.04:LTS: ruby-faraday, Ubuntu:25.10: ruby-faraday, Ubuntu:26.04:LTS: ruby-faraday&lt;/p&gt;
&lt;p&gt;Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday&amp;#39;s nested query parsing or URL-building paths. This vulnerability is fixed in 1.10.6 and 2.14.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-faraday, Ubuntu:16.04:LTS: ruby-faraday, Ubuntu:18.04:LTS: ruby-faraday, Ubuntu:20.04:LTS: ruby-faraday, Ubuntu:22.04:LTS: ruby-faraday, Ubuntu:24.04:LTS: ruby-faraday, Ubuntu:25.10: ruby-faraday, Ubuntu:26.04:LTS: ruby-faraday&lt;/p&gt;
&lt;p&gt;Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday&amp;#39;s nested query parsing or URL-building paths. This vulnerability is fixed in 1.10.6 and 2.14.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54297</guid>
    </item>
  </channel>
</rss>
