<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:56:07.166493+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-24570</id>
    <title>cnvd-2019-24570</title>
    <updated>2026-10-02T21:56:07.246049+00:00</updated>
    <content>cnvd-2019-24570</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-24570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-53430</id>
    <title>EUVD-2026-53430</title>
    <updated>2026-10-02T21:56:07.246091+00:00</updated>
    <content>EUVD-2026-53430</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-53430"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10184</id>
    <title>fkie_cve-2019-10184</title>
    <updated>2026-10-02T21:56:07.246104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-10184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w69w-jvc7-wjgv</id>
    <title>GHSA-w69w-jvc7-wjgv — Undertow Missing Authorization when requesting a protected directory without trailing slash</title>
    <updated>2026-10-02T21:56:07.246133+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.undertow:undertow-servlet</p>
<p>undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w69w-jvc7-wjgv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-10184</id>
    <title>gsd-2019-10184</title>
    <updated>2026-10-02T21:56:07.246157+00:00</updated>
    <content>gsd-2019-10184</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-10184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1257</id>
    <title>OESA-2025-1257 — undertow security update</title>
    <updated>2026-10-02T21:56:07.246168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: undertow, openEuler:20.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP3: undertow, openEuler:22.03-LTS-SP4: undertow, openEuler:24.03-LTS: undertow</p>
<p>Java web server using non-blocking IO

Security Fix(es):</p>
<p>undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.(CVE-2017-12196)</p>
<p>undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.(CVE-2019-10184)</p>
<p>A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user&amp;apos;s credentials from the log files.(CVE-2019-10212)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1257"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:2935</id>
    <title>RHSA-2019:2935 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 6 Security update</title>
    <updated>2026-10-02T21:56:07.246201+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undertow: Information leak in requests for directories without trailing slashes codehaus: incomplete fix for unsafe deserialization in jackson-databind vulnerabilities undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log files jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server. jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server via crafted JSON message. jackson-databind: default typing mishandling leading to remote code execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:2935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10184</id>
    <title>UBUNTU-CVE-2019-10184</title>
    <updated>2026-10-02T21:56:07.246229+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:20.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow</p>
<p>undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2754</id>
    <title>WID-SEC-W-2026-2754 — Red Hat Produkte: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:56:07.246253+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Single Sign On, Red Hat OpenShift Application Runtimes, Red Hat OpenShift Container Platform, Red Hat JBoss Enterprise Application Platform und Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen oder beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2754"/>
  </entry>
</feed>
