<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 02:59:55 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-13327 — Uv: uv: specially crafted zip archives lead to arbitrary code execution due to parsing differentials</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-13327</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; astral-sh uv, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI)&lt;/p&gt;
&lt;p&gt;A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that exploit parsing differentials, requiring user interaction to install an attacker-controlled package.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; astral-sh uv, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI)&lt;/p&gt;
&lt;p&gt;A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that exploit parsing differentials, requiring user interaction to install an attacker-controlled package.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-13327</guid>
    </item>
    <item>
      <title>GHSA-pqhf-p39g-3x64 — uv allows ZIP payload obfuscation through parsing differentials</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pqhf-p39g-3x64</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: uv&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In versions 0.9.5 and earlier of uv, ZIP archives were handled in a manner that enabled two parsing differentials against other components of the Python packaging ecosystem:&lt;/p&gt;
&lt;p&gt;1. Central directory entries in a ZIP archive can contain comment fields. However, uv would assume that these fields were not present, since they aren&amp;#39;t widely used. Consequently, a ZIP archive could be constructed where uv would interpret the contents of a central directory comment field as ZIP control structures (such as a new central directory entry), rather than skipping over them.
2. Both local file entries and central directory entries contain filename fields, which are used to place archive members on disk. These fields are arbitrary sequences of bytes, and may therefore be invalid or ambiguous. For example, they may contain ASCII null bytes, in which case different ZIP extractors behave differently: Python&amp;#39;s `zipfile` module truncates the filename at the first null, while uv would skip (not extract) any archive members whose filenames contained nulls. Because of this difference, a ZIP archive could be constructed that would extract differently across different Python package installers.&lt;/p&gt;
&lt;p&gt;In both cases, the outcome is that an attacker may be able to produce a ZIP with a consistent digest that expands differently with different Python package installers.&lt;/p&gt;
&lt;p&gt;Like with GHSA-8qf3-x8v5-2pj8, the impact of these differentials is limited by a number of factors:&lt;/p&gt;
&lt;p&gt;- To be compromised via this vu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: uv&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In versions 0.9.5 and earlier of uv, ZIP archives were handled in a manner that enabled two parsing differentials against other components of the Python packaging ecosystem:&lt;/p&gt;
&lt;p&gt;1. Central directory entries in a ZIP archive can contain comment fields. However, uv would assume that these fields were not present, since they aren&amp;#39;t widely used. Consequently, a ZIP archive could be constructed where uv would interpret the contents of a central directory comment field as ZIP control structures (such as a new central directory entry), rather than skipping over them.
2. Both local file entries and central directory entries contain filename fields, which are used to place archive members on disk. These fields are arbitrary sequences of bytes, and may therefore be invalid or ambiguous. For example, they may contain ASCII null bytes, in which case different ZIP extractors behave differently: Python&amp;#39;s `zipfile` module truncates the filename at the first null, while uv would skip (not extract) any archive members whose filenames contained nulls. Because of this difference, a ZIP archive could be constructed that would extract differently across different Python package installers.&lt;/p&gt;
&lt;p&gt;In both cases, the outcome is that an attacker may be able to produce a ZIP with a consistent digest that expands differently with different Python package installers.&lt;/p&gt;
&lt;p&gt;Like with GHSA-8qf3-x8v5-2pj8, the impact of these differentials is limited by a number of factors:&lt;/p&gt;
&lt;p&gt;- To be compromised via this vu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pqhf-p39g-3x64</guid>
    </item>
  </channel>
</rss>
