<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:17:46 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-57585</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-57585</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-msgpack, Alpaquita:25: py3-msgpack, Alpaquita:stream: py3-msgpack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-msgpack, Alpaquita:25: py3-msgpack, Alpaquita:stream: py3-msgpack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-57585</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2026-57585 — MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2026-57585</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.&lt;/p&gt;
&lt;p&gt;If the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;v1.2.1&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users should create a new Unpacker instead of reusing the same Unpacker after an error occurs.&lt;/p&gt;
&lt;p&gt;Applying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.&lt;/p&gt;
&lt;p&gt;Therefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.&lt;/p&gt;
&lt;p&gt;If the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;v1.2.1&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users should create a new Unpacker instead of reusing the same Unpacker after an error occurs.&lt;/p&gt;
&lt;p&gt;Applying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.&lt;/p&gt;
&lt;p&gt;Therefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2026-57585</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0873 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0873</link>
      <description>certfr-2026-avi-0873</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0873</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-DU27033 — Security fixes in apache-superset 5.0.0-r8</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-du27033</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-superset&lt;/p&gt;
&lt;p&gt;Package apache-superset version 5.0.0-r8 fixes 6 vulnerabilities: ghsa-537c-gmf6-5ccf, CVE-2026-34180, ghsa-6v7p-g79w-8964, CVE-2026-57585, CVE-2026-44405...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-superset&lt;/p&gt;
&lt;p&gt;Package apache-superset version 5.0.0-r8 fixes 6 vulnerabilities: ghsa-537c-gmf6-5ccf, CVE-2026-34180, ghsa-6v7p-g79w-8964, CVE-2026-57585, CVE-2026-44405...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-du27033</guid>
    </item>
    <item>
      <title>EUVD-2026-331783</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331783</link>
      <description>EUVD-2026-331783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331783</guid>
    </item>
    <item>
      <title>fkie_cve-2026-57585</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57585</link>
      <description>&lt;p&gt;MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack.  If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack.  If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-57585</guid>
    </item>
    <item>
      <title>GHSA-6v7p-g79w-8964 — MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6v7p-g79w-8964</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: msgpack&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.&lt;/p&gt;
&lt;p&gt;If the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;v1.2.1&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users should create a new Unpacker instead of reusing the same Unpacker after an error occurs.&lt;/p&gt;
&lt;p&gt;Applying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.&lt;/p&gt;
&lt;p&gt;Therefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: msgpack&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.&lt;/p&gt;
&lt;p&gt;If the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;v1.2.1&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users should create a new Unpacker instead of reusing the same Unpacker after an error occurs.&lt;/p&gt;
&lt;p&gt;Applying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.&lt;/p&gt;
&lt;p&gt;Therefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6v7p-g79w-8964</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-57585 — MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-57585</link>
      <description>msrc_CVE-2026-57585</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-57585</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11586-1 — python313-msgpack-1.2.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11586-1</link>
      <description>&lt;p&gt;python313-msgpack-1.2.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-msgpack-1.2.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11586-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3625</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3625</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: msgpack&lt;/p&gt;
&lt;p&gt;MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack.  If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: msgpack&lt;/p&gt;
&lt;p&gt;MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack.  If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3625</guid>
    </item>
    <item>
      <title>RHSA-2026:70965 — Red Hat Security Advisory: Red Hat AI Inference 3.4.5 (cpu)</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:70965</link>
      <description>&lt;p&gt;python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting vllm: vLLM: Denial of Service via unbounded video frame processing aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() vllm: vLLM: Arbitrary code execution via malicious HuggingFace model vllm: vLLM: Denial of Service via malformed tensor shape in speculative decoding Diffusers: Diffusers: Arbitrary remote code execution via `trust_remote_code` bypass diffusers: Diffusers: Arbitrary Code Execution via malicious model loading diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens starlette: Starlette: Security restriction bypass via malformed HTTP Host header vllm: starlette: vLLM: Critical authentication bypass allows unauthorized API access Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files vllm: vLLM: Denial of Service via malformed speculative decoding workload starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API msgpac…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting vllm: vLLM: Denial of Service via unbounded video frame processing aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() vllm: vLLM: Arbitrary code execution via malicious HuggingFace model vllm: vLLM: Denial of Service via malformed tensor shape in speculative decoding Diffusers: Diffusers: Arbitrary remote code execution via `trust_remote_code` bypass diffusers: Diffusers: Arbitrary Code Execution via malicious model loading diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens starlette: Starlette: Security restriction bypass via malformed HTTP Host header vllm: starlette: vLLM: Critical authentication bypass allows unauthorized API access Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files vllm: vLLM: Denial of Service via malformed speculative decoding workload starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API msgpac…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:70965</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22704-1 — Security update for python-msgpack</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22704-1</link>
      <description>&lt;p&gt;Security update for python-msgpack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-msgpack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22704-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-57585</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-57585</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:18.04:LTS: python-msgpack, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:20.04:LTS: python-msgpack, Ubuntu:Pro:20.04:LTS: python-pip, Ubuntu:22.04:LTS: python-msgpack, Ubuntu:Pro:22.04:LTS: python-pip, Ubuntu:24.04:LTS: python-msgpack, Ubuntu:24.04:LTS: python-srsly and 7 more&lt;/p&gt;
&lt;p&gt;MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack.  If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:18.04:LTS: python-msgpack, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:20.04:LTS: python-msgpack, Ubuntu:Pro:20.04:LTS: python-pip, Ubuntu:22.04:LTS: python-msgpack, Ubuntu:Pro:22.04:LTS: python-pip, Ubuntu:24.04:LTS: python-msgpack, Ubuntu:24.04:LTS: python-srsly and 7 more&lt;/p&gt;
&lt;p&gt;MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack.  If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-57585</guid>
    </item>
  </channel>
</rss>
