<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 18:34:45 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-00774</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00774</link>
      <description>bdu:2024-00774</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00774</guid>
    </item>
    <item>
      <title>EUVD-2026-196483</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-196483</link>
      <description>EUVD-2026-196483</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-196483</guid>
    </item>
    <item>
      <title>fkie_cve-2024-21484</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-21484</link>
      <description>&lt;p&gt;Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key.&#13;&#13; Workaround &#13;&#13;The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key.&#13;&#13; Workaround &#13;&#13;The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-21484</guid>
    </item>
    <item>
      <title>GHSA-rh63-9qcf-83gf — Marvin Attack of RSA and RSAOAEP decryption in jsrsasign</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rh63-9qcf-83gf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jsrsasign&lt;/p&gt;
&lt;p&gt;### Impact
RSA PKCS#1.5 or RSAOAEP ciphertexts may be decrypted by this Marvin attack vulnerability.&lt;/p&gt;
&lt;p&gt;### Patches
update to jsrsasign 11.0.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
Find and replace RSA and RSAOAEP decryption with other crypto library.&lt;/p&gt;
&lt;p&gt;### References
https://people.redhat.com/~hkario/marvin/
https://github.com/kjur/jsrsasign/issues/598
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6070732
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21484&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jsrsasign&lt;/p&gt;
&lt;p&gt;### Impact
RSA PKCS#1.5 or RSAOAEP ciphertexts may be decrypted by this Marvin attack vulnerability.&lt;/p&gt;
&lt;p&gt;### Patches
update to jsrsasign 11.0.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
Find and replace RSA and RSAOAEP decryption with other crypto library.&lt;/p&gt;
&lt;p&gt;### References
https://people.redhat.com/~hkario/marvin/
https://github.com/kjur/jsrsasign/issues/598
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6070732
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21484&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rh63-9qcf-83gf</guid>
    </item>
    <item>
      <title>gsd-2024-21484</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-21484</link>
      <description>gsd-2024-21484</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-21484</guid>
    </item>
    <item>
      <title>RHBA-2024:0928 — Red Hat Bug Fix Advisory: MTV 2.5.5 Images</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:0928</link>
      <description>&lt;p&gt;follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() jsrsasign: vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() jsrsasign: vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:0928</guid>
    </item>
  </channel>
</rss>
