<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:53:13.323020+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2020:4807</id>
    <title>ALSA-2020:4807 — Moderate: prometheus-jmx-exporter security update</title>
    <updated>2026-10-02T13:53:13.621525+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: prometheus-jmx-exporter</p>
<p>Prometheus JMX Exporter is a JMX to Prometheus exporter: a collector that can be configured to scrape and expose MBeans of a JMX target.</p>
<p>Security Fix(es):</p>
<p>* snakeyaml: Billion laughs attack via alias feature (CVE-2017-18640)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2020:4807"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-02625</id>
    <title>bdu:2021-02625</title>
    <updated>2026-10-02T13:53:13.621587+00:00</updated>
    <content>bdu:2021-02625</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-02625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-266</id>
    <title>certfr-2022-avi-266 — De multiples vulnérabilités ont été découvertes dans IBM WebSphere
Service Registry and Repository. Certaines d'entre e…</title>
    <updated>2026-10-02T13:53:13.621604+00:00</updated>
    <content>certfr-2022-avi-266</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-266"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-22682</id>
    <title>cnvd-2020-22682</title>
    <updated>2026-10-02T13:53:13.621620+00:00</updated>
    <content>cnvd-2020-22682</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-22682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-80393</id>
    <title>EUVD-2026-80393</title>
    <updated>2026-10-02T13:53:13.621631+00:00</updated>
    <content>EUVD-2026-80393</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-80393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-18640</id>
    <title>fkie_cve-2017-18640</title>
    <updated>2026-10-02T13:53:13.621641+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-18640"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rvwf-54qp-4r6v</id>
    <title>GHSA-rvwf-54qp-4r6v — SnakeYAML Entity Expansion during load operation</title>
    <updated>2026-10-02T13:53:13.621661+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.yaml:snakeyaml</p>
<p>The Alias feature in SnakeYAML 1.18 allows entity expansion during a load operation, a related issue to CVE-2003-1564.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rvwf-54qp-4r6v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-18640</id>
    <title>gsd-2017-18640</title>
    <updated>2026-10-02T13:53:13.621679+00:00</updated>
    <content>gsd-2017-18640</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-18640"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2022-000062</id>
    <title>jvndb-2022-000062</title>
    <updated>2026-10-02T13:53:13.621689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kaitai Struct: compiler provided by Kaitai team contains SnakeYAML library version 1.25, which is used in parsing .ksy files.
SnakeYAML version 1.25 expands recursive aliases unlimitedly (CWE-674), hence Katai Struct: compiler is vulnerable to a denial-of-service (DoS) attack by Billion Laughs Attack.

Taichi Kotake of Sterra Security Co.,Ltd. / Akatsuki Games Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2022-000062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2017-18640</id>
    <title>msrc_CVE-2017-18640 — The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003…</title>
    <updated>2026-10-02T13:53:13.621706+00:00</updated>
    <content>msrc_CVE-2017-18640</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2017-18640"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0855-1</id>
    <title>openSUSE-SU-2021:0855-1 — Security update for snakeyaml</title>
    <updated>2026-10-02T13:53:13.621722+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for snakeyaml</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0855-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:2603</id>
    <title>RHSA-2020:2603 — Red Hat Security Advisory: Red Hat build of Quarkus 1.3.4 security update</title>
    <updated>2026-10-02T13:53:13.621736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>snakeyaml: Billion laughs attack via alias feature</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:2603"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:1876-1</id>
    <title>SUSE-SU-2021:1876-1 — Security update for snakeyaml</title>
    <updated>2026-10-02T13:53:13.621750+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for snakeyaml</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:1876-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-18640</id>
    <title>UBUNTU-CVE-2017-18640</title>
    <updated>2026-10-02T13:53:13.621763+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: snakeyaml, Ubuntu:Pro:16.04:LTS: snakeyaml, Ubuntu:Pro:18.04:LTS: snakeyaml, Ubuntu:Pro:20.04:LTS: snakeyaml</p>
<p>The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-18640"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</id>
    <title>WID-SEC-W-2022-0770 — IBM DB2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:53:13.621784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770"/>
  </entry>
</feed>
