<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:28:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-341916</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341916</link>
      <description>EUVD-2026-341916</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341916</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59251</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59251</link>
      <description>&lt;p&gt;Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake.&lt;/p&gt;
&lt;p&gt;During RFC 5280 policy processing in public_key:pkix_path_validation/3, the certificate policy tree maintained by pubkey_policy_tree grows without an upper bound. When a certificate chain contains M policies per certificate and K certificates, the tree grows on the order of M^K nodes because pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2 extend the tree per policy per certificate. A modest chain with many policies per certificate is enough to pin BEAM schedulers and exhaust the node&amp;#39;s memory, taking down the entire VM. The attacker only needs to be able to present a certificate chain to the victim, which is the normal precondition for a TLS handshake, so exploitation succeeds against any incoming or outgoing TLS connection that validates the peer&amp;#39;s chain (the default for SSL/TLS clients and mutual-TLS servers).&lt;/p&gt;
&lt;p&gt;This is the same vulnerability class as OpenSSL&amp;#39;s X509_verify_cert policy tree DoS.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/public_key/src/pubkey_policy_tree.erl and program routines pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 26.2 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to public_key from 1.15 before 1.21.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake.&lt;/p&gt;
&lt;p&gt;During RFC 5280 policy processing in public_key:pkix_path_validation/3, the certificate policy tree maintained by pubkey_policy_tree grows without an upper bound. When a certificate chain contains M policies per certificate and K certificates, the tree grows on the order of M^K nodes because pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2 extend the tree per policy per certificate. A modest chain with many policies per certificate is enough to pin BEAM schedulers and exhaust the node&amp;#39;s memory, taking down the entire VM. The attacker only needs to be able to present a certificate chain to the victim, which is the normal precondition for a TLS handshake, so exploitation succeeds against any incoming or outgoing TLS connection that validates the peer&amp;#39;s chain (the default for SSL/TLS clients and mutual-TLS servers).&lt;/p&gt;
&lt;p&gt;This is the same vulnerability class as OpenSSL&amp;#39;s X509_verify_cert policy tree DoS.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/public_key/src/pubkey_policy_tree.erl and program routines pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 26.2 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to public_key from 1.15 before 1.21.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59251</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-59251 — Denial of service via exponential certificate policy tree growth in path validation</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-59251</link>
      <description>msrc_CVE-2026-59251</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-59251</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11559-1 — erlang-28.5.0.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11559-1</link>
      <description>&lt;p&gt;erlang-28.5.0.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;erlang-28.5.0.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11559-1</guid>
    </item>
    <item>
      <title>RHSA-2026:47009 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:47009</link>
      <description>&lt;p&gt;erlang-otp: epmd: Erlang OTP epmd: Remote Denial of Service via connection exhaustion erlang/otp: erts: otp: Erlang/OTP: Denial of Service via integer underflow in ETF decoding erlang/otp: Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance megaco: Erlang/OTP Megaco Flex Scanner: Remote code execution or denial of service via oversized message Erlang/OTP: public_key: Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;erlang-otp: epmd: Erlang OTP epmd: Remote Denial of Service via connection exhaustion erlang/otp: erts: otp: Erlang/OTP: Denial of Service via integer underflow in ETF decoding erlang/otp: Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance megaco: Erlang/OTP Megaco Flex Scanner: Remote code execution or denial of service via oversized message Erlang/OTP: public_key: Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:47009</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59251</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59251</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:26.04:LTS: erlang&lt;/p&gt;
&lt;p&gt;Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake. During RFC 5280 policy processing in public_key:pkix_path_validation/3, the certificate policy tree maintained by pubkey_policy_tree grows without an upper bound. When a certificate chain contains M policies per certificate and K certificates, the tree grows on the order of M^K nodes because pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2 extend the tree per policy per certificate. A modest chain with many policies per certificate is enough to pin BEAM schedulers and exhaust the node&amp;#39;s memory, taking down the entire VM. The attacker only needs to be able to present a certificate chain to the victim, which is the normal precondition for a TLS handshake, so exploitation succeeds against any incoming or outgoing TLS connection that validates the peer&amp;#39;s chain (the default for SSL/TLS clients and mutual-TLS servers). This is the same vulnerability class as OpenSSL&amp;#39;s X509_verify_cert policy tree DoS. This vulnerability is associated with program files lib/public_key/src/pubkey_policy_tree.erl and program routines pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2. This issue affects OTP from OTP 26.2 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to public_key from 1.15 before 1.21.4, 1…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:26.04:LTS: erlang&lt;/p&gt;
&lt;p&gt;Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake. During RFC 5280 policy processing in public_key:pkix_path_validation/3, the certificate policy tree maintained by pubkey_policy_tree grows without an upper bound. When a certificate chain contains M policies per certificate and K certificates, the tree grows on the order of M^K nodes because pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2 extend the tree per policy per certificate. A modest chain with many policies per certificate is enough to pin BEAM schedulers and exhaust the node&amp;#39;s memory, taking down the entire VM. The attacker only needs to be able to present a certificate chain to the victim, which is the normal precondition for a TLS handshake, so exploitation succeeds against any incoming or outgoing TLS connection that validates the peer&amp;#39;s chain (the default for SSL/TLS clients and mutual-TLS servers). This is the same vulnerability class as OpenSSL&amp;#39;s X509_verify_cert policy tree DoS. This vulnerability is associated with program files lib/public_key/src/pubkey_policy_tree.erl and program routines pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2. This issue affects OTP from OTP 26.2 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to public_key from 1.15 before 1.21.4, 1…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59251</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2533 — Erlang/OTP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2533</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Erlang/OTP ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen sowie Daten zu manipulieren oder offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Erlang/OTP ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen sowie Daten zu manipulieren oder offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2533</guid>
    </item>
  </channel>
</rss>
