<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:10:17 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:3254 — Important: container-tools:rhel8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:3254</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* buildah: full container escape at build time (CVE-2024-1753)
* golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)
* golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)
* golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786)
* jose-go: improper handling of highly compressed data (CVE-2024-28180)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* buildah: full container escape at build time (CVE-2024-1753)
* golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)
* golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)
* golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786)
* jose-go: improper handling of highly compressed data (CVE-2024-28180)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:3254</guid>
    </item>
    <item>
      <title>bdu:2024-01928</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01928</link>
      <description>bdu:2024-01928</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01928</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0514 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0514</link>
      <description>certfr-2024-avi-0514</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0514</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-SY26301 — Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-sy26301</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: buildah&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the buildah package. Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: buildah&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the buildah package. Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-sy26301</guid>
    </item>
    <item>
      <title>EUVD-2026-217366</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217366</link>
      <description>EUVD-2026-217366</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217366</guid>
    </item>
    <item>
      <title>fkie_cve-2024-28180</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-28180</link>
      <description>&lt;p&gt;Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-28180</guid>
    </item>
    <item>
      <title>GHSA-c5q2-7r4c-mv6g — Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c5q2-7r4c-mv6g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-jose/go-jose/v4, Go: github.com/go-jose/go-jose/v3, Go: gopkg.in/go-jose/go-jose.v2, Go: gopkg.in/square/go-jose.v2&lt;/p&gt;
&lt;p&gt;### Impact
An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). Thanks to Enze Wang@Alioth and Jianjun Chen@Zhongguancun Lab (@zer0yu and @chenjj) for reporting.&lt;/p&gt;
&lt;p&gt;### Patches
The problem is fixed in the following packages and versions:
- github.com/go-jose/go-jose/v4 version 4.0.1
- github.com/go-jose/go-jose/v3 version 3.0.3
- gopkg.in/go-jose/go-jose.v2 version 2.6.3&lt;/p&gt;
&lt;p&gt;The problem will not be fixed in the following package because the package is archived:
- gopkg.in/square/go-jose.v2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-jose/go-jose/v4, Go: github.com/go-jose/go-jose/v3, Go: gopkg.in/go-jose/go-jose.v2, Go: gopkg.in/square/go-jose.v2&lt;/p&gt;
&lt;p&gt;### Impact
An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). Thanks to Enze Wang@Alioth and Jianjun Chen@Zhongguancun Lab (@zer0yu and @chenjj) for reporting.&lt;/p&gt;
&lt;p&gt;### Patches
The problem is fixed in the following packages and versions:
- github.com/go-jose/go-jose/v4 version 4.0.1
- github.com/go-jose/go-jose/v3 version 3.0.3
- gopkg.in/go-jose/go-jose.v2 version 2.6.3&lt;/p&gt;
&lt;p&gt;The problem will not be fixed in the following package because the package is archived:
- gopkg.in/square/go-jose.v2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c5q2-7r4c-mv6g</guid>
    </item>
    <item>
      <title>gsd-2024-28180</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-28180</link>
      <description>gsd-2024-28180</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-28180</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-28180 — Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-28180</link>
      <description>msrc_CVE-2024-28180</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-28180</guid>
    </item>
    <item>
      <title>OESA-2024-1472 — cri-o security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1472</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: cri-o&lt;/p&gt;
&lt;p&gt;Open Container Initiative-based implementation of Kubernetes Container Runtime Interface.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.
(CVE-2024-28180)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: cri-o&lt;/p&gt;
&lt;p&gt;Open Container Initiative-based implementation of Kubernetes Container Runtime Interface.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.
(CVE-2024-28180)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1472</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13905-1 — cmctl-1.14.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13905-1</link>
      <description>&lt;p&gt;cmctl-1.14.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cmctl-1.14.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13905-1</guid>
    </item>
    <item>
      <title>RHBA-2025:1772 — Red Hat Bug Fix Advisory: Updated 7.1 container image is now available in the Red Hat Ecosystem Catalog</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:1772</link>
      <description>&lt;p&gt;golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON jose: resource exhaustion jose-go: improper handling of highly compressed data envoy: HTTP/2 CPU exhaustion due to CONTINUATION frame flood go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion keepalived: Integer overflow vulnerability in vrrp_ipsets_handler&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON jose: resource exhaustion jose-go: improper handling of highly compressed data envoy: HTTP/2 CPU exhaustion due to CONTINUATION frame flood go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion keepalived: Integer overflow vulnerability in vrrp_ipsets_handler&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:1772</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1987-2 — Security update for skopeo</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1987-2</link>
      <description>&lt;p&gt;Security update for skopeo&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for skopeo&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1987-2</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2024-28180</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28180</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.10: golang-github-go-jose-go-jose, Ubuntu:24.04:LTS: golang-github-go-jose-go-jose, Ubuntu:25.04: golang-github-go-jose-go-jose&lt;/p&gt;
&lt;p&gt;Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.10: golang-github-go-jose-go-jose, Ubuntu:24.04:LTS: golang-github-go-jose-go-jose, Ubuntu:25.04: golang-github-go-jose-go-jose&lt;/p&gt;
&lt;p&gt;Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28180</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0947 — Red Hat OpenShift: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0947</link>
      <description>&lt;p&gt;Ein entfernter authentifizierter Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter authentifizierter Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0947</guid>
    </item>
  </channel>
</rss>
