<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T09:53:34.698822+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-02465</id>
    <title>bdu:2019-02465</title>
    <updated>2026-10-07T09:53:34.715064+00:00</updated>
    <content>bdu:2019-02465</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-02465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-48394</id>
    <title>EUVD-2026-48394</title>
    <updated>2026-10-07T09:53:34.715104+00:00</updated>
    <content>EUVD-2026-48394</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-48394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-0223</id>
    <title>fkie_cve-2019-0223</title>
    <updated>2026-10-07T09:53:34.715119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-0223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5h6x-m52p-23ph</id>
    <title>Withdrawn: GHSA-5h6x-m52p-23ph — Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton</title>
    <updated>2026-10-07T09:53:34.715151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Maven: org.apache.qpid:proton-j</p>
<p>## Withdrawn Advisory
This advisory has been withdrawn because the vulnerability only affects the **Qpid Proton C library** and not `org.apache.qpid:proton-j`. This link has been maintained to preserve external references.</p>
<p>## Original Description</p>
<p>While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5h6x-m52p-23ph"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-0223</id>
    <title>gsd-2019-0223</title>
    <updated>2026-10-07T09:53:34.715180+00:00</updated>
    <content>gsd-2019-0223</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-0223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13808-1</id>
    <title>openSUSE-SU-2024:13808-1 — libqpid-proton-core10-0.38.0-2.1 on GA media</title>
    <updated>2026-10-07T09:53:34.715192+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libqpid-proton-core10-0.38.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13808-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2019:4199</id>
    <title>RHBA-2019:4199 — Red Hat Bug Fix Advisory: CloudForms 5.0 bug fix and enhancement update</title>
    <updated>2026-10-07T09:53:34.715210+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bootstrap: XSS in the data-target attribute qpid-proton: TLS Man in the Middle Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2019:4199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1074-1</id>
    <title>SUSE-SU-2024:1074-1 — Security update for qpid-proton</title>
    <updated>2026-10-07T09:53:34.715243+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for qpid-proton</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1074-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0223</id>
    <title>UBUNTU-CVE-2019-0223</title>
    <updated>2026-10-07T09:53:34.715257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: qpid-proton, Ubuntu:18.04:LTS: qpid-proton</p>
<p>While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0223"/>
  </entry>
</feed>
