<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:18:13.505646+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-06063</id>
    <title>cnvd-2018-06063</title>
    <updated>2026-10-03T07:18:13.561263+00:00</updated>
    <content>cnvd-2018-06063</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-06063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-63259</id>
    <title>EUVD-2026-63259</title>
    <updated>2026-10-03T07:18:13.561306+00:00</updated>
    <content>EUVD-2026-63259</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-63259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-7536</id>
    <title>fkie_cve-2018-7536</title>
    <updated>2026-10-03T07:18:13.561320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-7536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r28v-mw67-m5p9</id>
    <title>GHSA-r28v-mw67-m5p9 — Django denial-of-service possibility in urlize and urlizetrunc template filters</title>
    <updated>2026-10-03T07:18:13.561352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Django</p>
<p>An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The `django.utils.html.urlize()` function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The `urlize()` function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r28v-mw67-m5p9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-7536</id>
    <title>gsd-2018-7536</title>
    <updated>2026-10-03T07:18:13.561378+00:00</updated>
    <content>gsd-2018-7536</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-7536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2018:0651-1</id>
    <title>openSUSE-SU-2018:0651-1 — Security update for python-Django</title>
    <updated>2026-10-03T07:18:13.561391+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Django</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2018:0651-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2018-5</id>
    <title>PYSEC-2018-5</title>
    <updated>2026-10-03T07:18:13.561408+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: django</p>
<p>An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2018-5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2927</id>
    <title>RHSA-2018:2927 — Red Hat Security Advisory: Satellite 6.4 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T07:18:13.561427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bouncycastle: Information disclosure in GCMBlockCipher bouncycastle: DSA does not fully validate ASN.1 encoding during signature verification allowing for injection of unsigned data bouncycastle: Information leak in AESFastEngine class bouncycastle: Carry propagation bug in math.raw.Nat??? class bouncycastle: Information exposure in DSA signature generation via timing attack bouncycastle: ECDSA improper validation of ASN.1 encoding of signature bouncycastle: DSA key pair generator generates a weak private key by default bouncycastle: DHIES implementation allowed the use of ECB mode bouncycastle: DHIES/ECIES CBC modes are vulnerable to padding oracle attack bouncycastle: Other party DH public keys are not fully validated bouncycastle: ECIES implementation allowed the use of ECB mode logback: Serialization vulnerability in SocketServer and ServerSocketReceiver python-django: Open redirect and possible XSS attack via user-supplied numeric redirect URLs hibernate-validator: Privilege escalation when running under the security manager puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions puppet: Environment leakage in puppet-agent 6: XSS in discovery rule filter autocomplete functionality jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525) foreman: Stored XSS in fact name or value pulp: sensitive credentials revealed through the API foreman: SQL injection due to improper handling of the widget…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:0973-1</id>
    <title>SUSE-SU-2018:0973-1 — Security update for python-Django</title>
    <updated>2026-10-03T07:18:13.561481+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Django</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:0973-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-7536</id>
    <title>UBUNTU-CVE-2018-7536</title>
    <updated>2026-10-03T07:18:13.561499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: python-django, Ubuntu:16.04:LTS: python-django</p>
<p>An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-7536"/>
  </entry>
</feed>
