<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:40:18 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CO34001 — Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-co34001</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: boring-registry&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the boring-registry package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: boring-registry&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the boring-registry package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-co34001</guid>
    </item>
    <item>
      <title>EUVD-2026-368015</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368015</link>
      <description>EUVD-2026-368015</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368015</guid>
    </item>
    <item>
      <title>fkie_cve-2026-84445</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84445</link>
      <description>&lt;p&gt;gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-84445</guid>
    </item>
    <item>
      <title>GHSA-2v4p-qf9q-27wj — gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2v4p-qf9q-27wj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: google.golang.org/grpc&lt;/p&gt;
&lt;p&gt;A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS).&lt;/p&gt;
&lt;p&gt;Servers built with `xds.NewGRPCServer` install an xDS routing interceptor on every RPC. This interceptor looks up the request’s `:authority` header to pick a virtual host. The HTTP/2 server transport previously accepted requests that had neither `:authority` nor `Host`. When this happened, the xDS routing interceptor attempted to access the first element of an empty slice of authorities, leading to an index out of bounds panic. Since the per-RPC goroutine does not recover from panics, the entire server process would terminate.&lt;/p&gt;
&lt;p&gt;This panic occurs in the interceptor pipeline, meaning the transport credentials handshake (TLS, mTLS, or ALTS) and HTTP/2 connection establishment must complete successfully before the crafted request can reach this logic.
- Insecure/Standard TLS: If the server permits insecure (plaintext) connections or standard credentials (where client certs are not checked), any unauthenticated remote attacker can trigger the crash.
- mTLS / ALTS: If strict transport-level authentication is enforced at the network edge or transport layer (e.g., requiring a valid client certificate), the attacker must possess valid transport credentials to initiate the stream and trigger the panic.&lt;/p&gt;
&lt;p&gt;### Impact
An attacker can cause a complete outage of the gRPC server…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: google.golang.org/grpc&lt;/p&gt;
&lt;p&gt;A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS).&lt;/p&gt;
&lt;p&gt;Servers built with `xds.NewGRPCServer` install an xDS routing interceptor on every RPC. This interceptor looks up the request’s `:authority` header to pick a virtual host. The HTTP/2 server transport previously accepted requests that had neither `:authority` nor `Host`. When this happened, the xDS routing interceptor attempted to access the first element of an empty slice of authorities, leading to an index out of bounds panic. Since the per-RPC goroutine does not recover from panics, the entire server process would terminate.&lt;/p&gt;
&lt;p&gt;This panic occurs in the interceptor pipeline, meaning the transport credentials handshake (TLS, mTLS, or ALTS) and HTTP/2 connection establishment must complete successfully before the crafted request can reach this logic.
- Insecure/Standard TLS: If the server permits insecure (plaintext) connections or standard credentials (where client certs are not checked), any unauthenticated remote attacker can trigger the crash.
- mTLS / ALTS: If strict transport-level authentication is enforced at the network edge or transport layer (e.g., requiring a valid client certificate), the attacker must possess valid transport credentials to initiate the stream and trigger the panic.&lt;/p&gt;
&lt;p&gt;### Impact
An attacker can cause a complete outage of the gRPC server…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2v4p-qf9q-27wj</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-84445 — gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers in the xDS servers</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-84445</link>
      <description>msrc_CVE-2026-84445</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-84445</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11686-1 — helm3-3.21.3-8.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11686-1</link>
      <description>&lt;p&gt;helm3-3.21.3-8.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;helm3-3.21.3-8.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11686-1</guid>
    </item>
    <item>
      <title>RHSA-2026:70593 — Red Hat Security Advisory: Network Observability 1.12.3 for OpenShift</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:70593</link>
      <description>&lt;p&gt;encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages github.com/gopacket/gopacket: gopacket: Remote Denial of Service via crafted packet processing nanoid: nanoid: Denial of Service via infinite loop in random ID generation fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages github.com/gopacket/gopacket: gopacket: Remote Denial of Service via crafted packet processing nanoid: nanoid: Denial of Service via infinite loop in random ID generation fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:70593</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23506-1 — Security update for helm</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23506-1</link>
      <description>&lt;p&gt;Security update for helm&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for helm&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23506-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3605 — Red Hat Enterprise Linux (rhc): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3605</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (rhc) ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (rhc) ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3605</guid>
    </item>
  </channel>
</rss>
