<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 12:31:10 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-21728 — Tempo query limit results in unbounded memory allocation</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-21728</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Grafana Tempo, Grafana Enterprise Traces (GET), Red Hat Multicluster Global Hub 1.3.4, Red Hat Multicluster Global Hub 1.4.5, Red Hat Multicluster Global Hub 1.6.5, Red Hat Multicluster Global Hub 1.7.0, Red Hat multicluster global hub 1.5.3, Red Hat Logging Subsystem for Red Hat OpenShift, Red Hat Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2 and 6 more&lt;/p&gt;
&lt;p&gt;Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.&lt;/p&gt;
&lt;p&gt;Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Grafana Tempo, Grafana Enterprise Traces (GET), Red Hat Multicluster Global Hub 1.3.4, Red Hat Multicluster Global Hub 1.4.5, Red Hat Multicluster Global Hub 1.6.5, Red Hat Multicluster Global Hub 1.7.0, Red Hat multicluster global hub 1.5.3, Red Hat Logging Subsystem for Red Hat OpenShift, Red Hat Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2 and 6 more&lt;/p&gt;
&lt;p&gt;Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.&lt;/p&gt;
&lt;p&gt;Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-21728</guid>
    </item>
    <item>
      <title>GHSA-jpcw-4wr7-c3vq — kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter w…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jpcw-4wr7-c3vq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/getkin/kin-openapi&lt;/p&gt;
&lt;p&gt;| Field | Value |
|---|---|
| Ecosystem | Go |
| Package | `github.com/getkin/kin-openapi` |
| Affected versions | `&amp;lt;= 0.143.0` (introduced in `v0.2.0`, PR #90, 2019-05-07; reproduced on `HEAD` `30e2923`) |
| Patched versions | 0.144.0 |
---&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`openapi3filter.ValidateRequest` contains a NULL-pointer-dereference denial of service: any **unauthenticated** client can crash the request-validation path with a **single** HTTP request. When an operation declares a `content` parameter (as opposed to a `schema` parameter) whose media type object has **no `schema`**, request validation dereferences that missing schema and panics. The document is legal under the OpenAPI Specification — kin-openapi&amp;#39;s own `doc.Validate()` accepts it — and the defect affects **both OpenAPI 3.0.x and 3.1.x**. Depending on how the library is wired into the server (see Impact), this ranges from a per-request abort with unbounded panic-log growth to a full remote process crash.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The decoder used for `content` parameters when no custom `ParamDecoder` is configured (the library default), `defaultContentParameterDecoder`, dereferences the media-type schema without a nil check.&lt;/p&gt;
&lt;p&gt;`openapi3filter/req_resp_decoder.go`, around line 197:&lt;/p&gt;
&lt;p&gt;```go
mt := content.Get(&amp;#34;application/json&amp;#34;)
if mt == nil {                       // media-type OBJECT is guarded ...
    err = fmt.Errorf(&amp;#34;parameter %q has no content schema&amp;#34;, param.Name)
    return
}
outSchema = mt.Schema.Value          // ... but mt.Schema…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/getkin/kin-openapi&lt;/p&gt;
&lt;p&gt;| Field | Value |
|---|---|
| Ecosystem | Go |
| Package | `github.com/getkin/kin-openapi` |
| Affected versions | `&amp;lt;= 0.143.0` (introduced in `v0.2.0`, PR #90, 2019-05-07; reproduced on `HEAD` `30e2923`) |
| Patched versions | 0.144.0 |
---&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`openapi3filter.ValidateRequest` contains a NULL-pointer-dereference denial of service: any **unauthenticated** client can crash the request-validation path with a **single** HTTP request. When an operation declares a `content` parameter (as opposed to a `schema` parameter) whose media type object has **no `schema`**, request validation dereferences that missing schema and panics. The document is legal under the OpenAPI Specification — kin-openapi&amp;#39;s own `doc.Validate()` accepts it — and the defect affects **both OpenAPI 3.0.x and 3.1.x**. Depending on how the library is wired into the server (see Impact), this ranges from a per-request abort with unbounded panic-log growth to a full remote process crash.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The decoder used for `content` parameters when no custom `ParamDecoder` is configured (the library default), `defaultContentParameterDecoder`, dereferences the media-type schema without a nil check.&lt;/p&gt;
&lt;p&gt;`openapi3filter/req_resp_decoder.go`, around line 197:&lt;/p&gt;
&lt;p&gt;```go
mt := content.Get(&amp;#34;application/json&amp;#34;)
if mt == nil {                       // media-type OBJECT is guarded ...
    err = fmt.Errorf(&amp;#34;parameter %q has no content schema&amp;#34;, param.Name)
    return
}
outSchema = mt.Schema.Value          // ... but mt.Schema…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jpcw-4wr7-c3vq</guid>
    </item>
  </channel>
</rss>
