<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:16:57.492662+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-02260</id>
    <title>bdu:2020-02260</title>
    <updated>2026-10-03T00:16:57.508452+00:00</updated>
    <content>bdu:2020-02260</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-02260"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-41646</id>
    <title>cnvd-2019-41646</title>
    <updated>2026-10-03T00:16:57.508505+00:00</updated>
    <content>cnvd-2019-41646</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-41646"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-53429</id>
    <title>EUVD-2026-53429</title>
    <updated>2026-10-03T00:16:57.508522+00:00</updated>
    <content>EUVD-2026-53429</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-53429"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10174</id>
    <title>fkie_cve-2019-10174</title>
    <updated>2026-10-03T00:16:57.508535+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-10174"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h47x-2j37-fw5m</id>
    <title>GHSA-h47x-2j37-fw5m — Use of Externally-Controlled Input to Select Classes or Code in Infinispan</title>
    <updated>2026-10-03T00:16:57.508569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.infinispan:infinispan-core</p>
<p>A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h47x-2j37-fw5m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-10174</id>
    <title>gsd-2019-10174</title>
    <updated>2026-10-03T00:16:57.508596+00:00</updated>
    <content>gsd-2019-10174</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-10174"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1667</id>
    <title>OESA-2024-1667 — infinispan security update</title>
    <updated>2026-10-03T00:16:57.508608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: infinispan, openEuler:20.03-LTS-SP4: infinispan, openEuler:22.03-LTS: infinispan, openEuler:22.03-LTS-SP1: infinispan, openEuler:22.03-LTS-SP2: infinispan, openEuler:22.03-LTS-SP3: infinispan</p>
<p>Infinispan is an extremely scalable, highly available data grid platform - 100% open source, and written in Java. The purpose of Infinispan is to expose a data structure that is highly concurrent, designed ground-up to make the most of modern multi-processor/multi-core architectures while at the same time providing distributed cache capabilities.  At its core Infinispan exposes a Cache interface which extends java.util.Map. It is also optionally is backed by a peer-to-peer network architecture to distribute state efficiently around a data grid.

Security Fix(es):

A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan&amp;apos;s privileges. The attacker can use reflection to introduce new, malicious behavior into the application.(CVE-2019-10174)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:3901</id>
    <title>RHSA-2019:3901 — Red Hat Security Advisory: Red Hat OpenShift Application Runtimes Vert.x 3.8.3 security update</title>
    <updated>2026-10-03T00:16:57.508641+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution jackson-databind: default typing mishandling leading to remote code execution netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in classes of the ehcache package</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:3901"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1926</id>
    <title>WID-SEC-W-2024-1926 — Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-03T00:16:57.508679+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform auf Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen preiszugeben, Dateien und Daten zu manipulieren oder Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1926"/>
  </entry>
</feed>
