<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 17:04:50 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-203320</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-203320</link>
      <description>EUVD-2026-203320</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-203320</guid>
    </item>
    <item>
      <title>fkie_cve-2024-51502</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-51502</link>
      <description>&lt;p&gt;loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. This issue has been addressed in release version 0.4.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. This issue has been addressed in release version 0.4.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-51502</guid>
    </item>
    <item>
      <title>GHSA-7vm6-qwh5-9x44 — loona-hpack Panic Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7vm6-qwh5-9x44</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: loona-hpack&lt;/p&gt;
&lt;p&gt;### Summary
`loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in https://github.com/mlalic/hpack-rs/issues/11&lt;/p&gt;
&lt;p&gt;### Details
The original includes a very nice description of the problem, as well as an easy-enough fix for it.&lt;/p&gt;
&lt;p&gt;### PoC
The original example pretty much still applies:
```rust
use loona_hpack::Decoder;&lt;/p&gt;
&lt;p&gt;pub fn main() {
    let input = &amp;amp;[0x3f];
    let mut decoder = Decoder::new();
    let _ = decoder.decode(input);
}
```&lt;/p&gt;
&lt;p&gt;### Impact
From the original:
`All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. A patched version of the crate is available on [crates.io](https://crates.io/crates/hpack-patched) under the name hpack-patched. See [Cargo&amp;#39;s documentation on overriding dependencies](https://doc.rust-lang.org/cargo/reference/overriding-dependencies.html) for more information.`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: loona-hpack&lt;/p&gt;
&lt;p&gt;### Summary
`loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in https://github.com/mlalic/hpack-rs/issues/11&lt;/p&gt;
&lt;p&gt;### Details
The original includes a very nice description of the problem, as well as an easy-enough fix for it.&lt;/p&gt;
&lt;p&gt;### PoC
The original example pretty much still applies:
```rust
use loona_hpack::Decoder;&lt;/p&gt;
&lt;p&gt;pub fn main() {
    let input = &amp;amp;[0x3f];
    let mut decoder = Decoder::new();
    let _ = decoder.decode(input);
}
```&lt;/p&gt;
&lt;p&gt;### Impact
From the original:
`All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. A patched version of the crate is available on [crates.io](https://crates.io/crates/hpack-patched) under the name hpack-patched. See [Cargo&amp;#39;s documentation on overriding dependencies](https://doc.rust-lang.org/cargo/reference/overriding-dependencies.html) for more information.`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7vm6-qwh5-9x44</guid>
    </item>
  </channel>
</rss>
