<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 12:04:43 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-337124</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337124</link>
      <description>EUVD-2026-337124</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337124</guid>
    </item>
    <item>
      <title>fkie_cve-2024-23680</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23680</link>
      <description>&lt;p&gt;AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-23680</guid>
    </item>
    <item>
      <title>GHSA-55xh-53m6-936r — Improper Verification of Cryptographic Signature in aws-encryption-sdk-java</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-55xh-53m6-936r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.amazonaws:aws-encryption-sdk-java&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This advisory addresses several LOW severity issues with streaming signed messages and restricting processing of certain types of invalid messages.&lt;/p&gt;
&lt;p&gt;This update addresses an issue where certain invalid ECDSA signatures incorrectly passed validation. These signatures provide defense in depth and there is no impact on the integrity of decrypted plaintext.&lt;/p&gt;
&lt;p&gt;This ESDK supports a streaming mode where callers may stream the plaintext of signed messages before the ECDSA signature is validated. In addition to these signatures, the ESDK uses AES-GCM encryption and all plaintext is verified before being released to a caller. There is no impact on the integrity of the ciphertext or decrypted plaintext, however some callers may rely on the the ECDSA signature for non-repudiation. Without validating the ECDSA signature, an actor with trusted KMS permissions to decrypt a message may also be able to encrypt messages. This update introduces a new API for callers who wish to stream only unsigned messages.&lt;/p&gt;
&lt;p&gt;For customers who process ESDK messages from untrusted sources, this update also introduces a new configuration to limit the number of Encrypted Data Keys (EDKs) that the ESDK will attempt to process per message. This configuration provides customers with a way to limit the number of AWS KMS Decrypt API calls that the ESDK will make per message. This setting will reject messages with more EDKs than the configured limit.&lt;/p&gt;
&lt;p&gt;Finally, this update adds early rejection of invalid me…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.amazonaws:aws-encryption-sdk-java&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This advisory addresses several LOW severity issues with streaming signed messages and restricting processing of certain types of invalid messages.&lt;/p&gt;
&lt;p&gt;This update addresses an issue where certain invalid ECDSA signatures incorrectly passed validation. These signatures provide defense in depth and there is no impact on the integrity of decrypted plaintext.&lt;/p&gt;
&lt;p&gt;This ESDK supports a streaming mode where callers may stream the plaintext of signed messages before the ECDSA signature is validated. In addition to these signatures, the ESDK uses AES-GCM encryption and all plaintext is verified before being released to a caller. There is no impact on the integrity of the ciphertext or decrypted plaintext, however some callers may rely on the the ECDSA signature for non-repudiation. Without validating the ECDSA signature, an actor with trusted KMS permissions to decrypt a message may also be able to encrypt messages. This update introduces a new API for callers who wish to stream only unsigned messages.&lt;/p&gt;
&lt;p&gt;For customers who process ESDK messages from untrusted sources, this update also introduces a new configuration to limit the number of Encrypted Data Keys (EDKs) that the ESDK will attempt to process per message. This configuration provides customers with a way to limit the number of AWS KMS Decrypt API calls that the ESDK will make per message. This setting will reject messages with more EDKs than the configured limit.&lt;/p&gt;
&lt;p&gt;Finally, this update adds early rejection of invalid me…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-55xh-53m6-936r</guid>
    </item>
    <item>
      <title>gsd-2024-23680</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-23680</link>
      <description>gsd-2024-23680</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-23680</guid>
    </item>
  </channel>
</rss>
