<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 01:56:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-370951</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-370951</link>
      <description>EUVD-2026-370951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-370951</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55149</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55149</link>
      <description>&lt;p&gt;Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the value to make([]string, numParts) without checking that the value is positive or reasonably bounded. Requests to /validate and /_external-auth-:id reach JWTCacheHandler in pkg/jwtmanager/jwtcache.go, FindJWT in pkg/jwtmanager/jwtmanager.go, and the vulnerable cookie reassembly before JWT validation, so no account or valid session is required. A cookie name such as VouchCookie_1of10000000000 causes an attempted slice allocation of roughly 160 GB and a fatal Go runtime out-of-memory condition, allowing one request to crash the authentication proxy and repeated requests to sustain unavailability. This vulnerability is fixed in 0.48.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the value to make([]string, numParts) without checking that the value is positive or reasonably bounded. Requests to /validate and /_external-auth-:id reach JWTCacheHandler in pkg/jwtmanager/jwtcache.go, FindJWT in pkg/jwtmanager/jwtmanager.go, and the vulnerable cookie reassembly before JWT validation, so no account or valid session is required. A cookie name such as VouchCookie_1of10000000000 causes an attempted slice allocation of roughly 160 GB and a fatal Go runtime out-of-memory condition, allowing one request to crash the authentication proxy and repeated requests to sustain unavailability. This vulnerability is fixed in 0.48.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55149</guid>
    </item>
    <item>
      <title>GHSA-qqff-5854-px68 — vouch-proxy has an Unbounded Multipart Cookie Allocation DoS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qqff-5854-px68</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/vouch/vouch-proxy&lt;/p&gt;
&lt;p&gt;## Unbounded Multipart Cookie Allocation DoS in vouch-proxy&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;vouch-proxy v0.47.2 contains an unauthenticated remote denial-of-service vulnerability in its multipart cookie reassembly logic. The `/validate` endpoint parses the total cookie part count directly from the attacker-controlled cookie name (e.g., `VouchCookie_1of&amp;lt;N&amp;gt;`) and passes it without any bounds check to `make([]string, N)`. A single HTTP request with `N=10000000000` causes the Go runtime to attempt a ~160 GB heap allocation, triggering a fatal out-of-memory error that crashes the server process immediately. No authentication or prior session is required.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in `pkg/cookie/cookie.go`. The `Cookie()` function iterates over all cookies in the request, identifies multipart cookies by the `_NofM` suffix in their name, and initializes the reassembly slice on the first matching cookie:&lt;/p&gt;
&lt;p&gt;```go
// pkg/cookie/cookie.go:123–130
xOFy := strings.Replace(cookie.Name, cookieUnder, &amp;#34;&amp;#34;, 1)
xyArray := strings.Split(xOFy, &amp;#34;of&amp;#34;)
if numParts == -1 {
    if numParts, err = strconv.Atoi(xyArray[1]); err != nil {
        return &amp;#34;&amp;#34;, fmt.Errorf(&amp;#34;multipart cookie fail: %s&amp;#34;, err)
    }
    cookieParts = make([]string, numParts)  // sink: unbounded allocation
}
```&lt;/p&gt;
&lt;p&gt;The value in `xyArray[1]` comes directly from the cookie name supplied by the client. There is no maximum value check, no positive-range assertion, and no format validation before `strconv.Atoi` parses it. The result is used as…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/vouch/vouch-proxy&lt;/p&gt;
&lt;p&gt;## Unbounded Multipart Cookie Allocation DoS in vouch-proxy&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;vouch-proxy v0.47.2 contains an unauthenticated remote denial-of-service vulnerability in its multipart cookie reassembly logic. The `/validate` endpoint parses the total cookie part count directly from the attacker-controlled cookie name (e.g., `VouchCookie_1of&amp;lt;N&amp;gt;`) and passes it without any bounds check to `make([]string, N)`. A single HTTP request with `N=10000000000` causes the Go runtime to attempt a ~160 GB heap allocation, triggering a fatal out-of-memory error that crashes the server process immediately. No authentication or prior session is required.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in `pkg/cookie/cookie.go`. The `Cookie()` function iterates over all cookies in the request, identifies multipart cookies by the `_NofM` suffix in their name, and initializes the reassembly slice on the first matching cookie:&lt;/p&gt;
&lt;p&gt;```go
// pkg/cookie/cookie.go:123–130
xOFy := strings.Replace(cookie.Name, cookieUnder, &amp;#34;&amp;#34;, 1)
xyArray := strings.Split(xOFy, &amp;#34;of&amp;#34;)
if numParts == -1 {
    if numParts, err = strconv.Atoi(xyArray[1]); err != nil {
        return &amp;#34;&amp;#34;, fmt.Errorf(&amp;#34;multipart cookie fail: %s&amp;#34;, err)
    }
    cookieParts = make([]string, numParts)  // sink: unbounded allocation
}
```&lt;/p&gt;
&lt;p&gt;The value in `xyArray[1]` comes directly from the cookie name supplied by the client. There is no maximum value check, no positive-range assertion, and no format validation before `strconv.Atoi` parses it. The result is used as…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qqff-5854-px68</guid>
    </item>
  </channel>
</rss>
