<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:30:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-368245</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368245</link>
      <description>EUVD-2026-368245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368245</guid>
    </item>
    <item>
      <title>fkie_cve-2026-82435</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-82435</link>
      <description>&lt;p&gt;Description&lt;/p&gt;
&lt;p&gt;The worker&amp;#39;s Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline
and acts on frames before any authentication has taken place. It allocated buffers sized from a
length field carried in the frame, so a single frame from an unauthenticated peer able to reach a worker
slot port could drive a large allocation.&lt;/p&gt;
&lt;p&gt;`storm.messaging.netty.authentication` defaults to false, and the decoder runs before the handler that
enforces it in any case, so no credentials are required. The attacker needs only TCP reachability to a
worker port.&lt;/p&gt;
&lt;p&gt;The effect of a single frame at the default 768 MB worker heap has not been measured to distinguish
sustained worker loss from transient garbage-collection pressure. The severity assigned to this advisory
reflects the more conservative reading; consumers who require a precise figure should test against their own
worker heap configuration.&lt;/p&gt;
&lt;p&gt;Mitigation&lt;/p&gt;
&lt;p&gt;Upgrade to 3.1.0, where frames are decoded only after the handshake completes.&lt;/p&gt;
&lt;p&gt;Users who cannot upgrade immediately should ensure that worker slot ports are reachable only from within the
cluster, as the security model already recommends, and should enable
`storm.messaging.netty.authentication` where the deployment permits it.&lt;/p&gt;
&lt;p&gt;Credit&lt;/p&gt;
&lt;p&gt;The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Description&lt;/p&gt;
&lt;p&gt;The worker&amp;#39;s Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline
and acts on frames before any authentication has taken place. It allocated buffers sized from a
length field carried in the frame, so a single frame from an unauthenticated peer able to reach a worker
slot port could drive a large allocation.&lt;/p&gt;
&lt;p&gt;`storm.messaging.netty.authentication` defaults to false, and the decoder runs before the handler that
enforces it in any case, so no credentials are required. The attacker needs only TCP reachability to a
worker port.&lt;/p&gt;
&lt;p&gt;The effect of a single frame at the default 768 MB worker heap has not been measured to distinguish
sustained worker loss from transient garbage-collection pressure. The severity assigned to this advisory
reflects the more conservative reading; consumers who require a precise figure should test against their own
worker heap configuration.&lt;/p&gt;
&lt;p&gt;Mitigation&lt;/p&gt;
&lt;p&gt;Upgrade to 3.1.0, where frames are decoded only after the handshake completes.&lt;/p&gt;
&lt;p&gt;Users who cannot upgrade immediately should ensure that worker slot ports are reachable only from within the
cluster, as the security model already recommends, and should enable
`storm.messaging.netty.authentication` where the deployment permits it.&lt;/p&gt;
&lt;p&gt;Credit&lt;/p&gt;
&lt;p&gt;The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-82435</guid>
    </item>
    <item>
      <title>GHSA-3mpj-29mm-p7wr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3mpj-29mm-p7wr</link>
      <description>&lt;p&gt;Description&lt;/p&gt;
&lt;p&gt;The worker&amp;#39;s Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline
and acts on frames before any authentication has taken place. It allocated buffers sized from a
length field carried in the frame, so a single frame from an unauthenticated peer able to reach a worker
slot port could drive a large allocation.&lt;/p&gt;
&lt;p&gt;`storm.messaging.netty.authentication` defaults to false, and the decoder runs before the handler that
enforces it in any case, so no credentials are required. The attacker needs only TCP reachability to a
worker port.&lt;/p&gt;
&lt;p&gt;The effect of a single frame at the default 768 MB worker heap has not been measured to distinguish
sustained worker loss from transient garbage-collection pressure. The severity assigned to this advisory
reflects the more conservative reading; consumers who require a precise figure should test against their own
worker heap configuration.&lt;/p&gt;
&lt;p&gt;Mitigation&lt;/p&gt;
&lt;p&gt;Upgrade to 3.1.0, where frames are decoded only after the handshake completes.&lt;/p&gt;
&lt;p&gt;Users who cannot upgrade immediately should ensure that worker slot ports are reachable only from within the
cluster, as the security model already recommends, and should enable
`storm.messaging.netty.authentication` where the deployment permits it.&lt;/p&gt;
&lt;p&gt;Credit&lt;/p&gt;
&lt;p&gt;The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Description&lt;/p&gt;
&lt;p&gt;The worker&amp;#39;s Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline
and acts on frames before any authentication has taken place. It allocated buffers sized from a
length field carried in the frame, so a single frame from an unauthenticated peer able to reach a worker
slot port could drive a large allocation.&lt;/p&gt;
&lt;p&gt;`storm.messaging.netty.authentication` defaults to false, and the decoder runs before the handler that
enforces it in any case, so no credentials are required. The attacker needs only TCP reachability to a
worker port.&lt;/p&gt;
&lt;p&gt;The effect of a single frame at the default 768 MB worker heap has not been measured to distinguish
sustained worker loss from transient garbage-collection pressure. The severity assigned to this advisory
reflects the more conservative reading; consumers who require a precise figure should test against their own
worker heap configuration.&lt;/p&gt;
&lt;p&gt;Mitigation&lt;/p&gt;
&lt;p&gt;Upgrade to 3.1.0, where frames are decoded only after the handshake completes.&lt;/p&gt;
&lt;p&gt;Users who cannot upgrade immediately should ensure that worker slot ports are reachable only from within the
cluster, as the security model already recommends, and should enable
`storm.messaging.netty.authentication` where the deployment permits it.&lt;/p&gt;
&lt;p&gt;Credit&lt;/p&gt;
&lt;p&gt;The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3mpj-29mm-p7wr</guid>
    </item>
  </channel>
</rss>
