<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T18:56:22.744451+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-57715</id>
    <title>EUVD-2026-57715</title>
    <updated>2026-10-10T18:56:22.748786+00:00</updated>
    <content>EUVD-2026-57715</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-57715"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-16370</id>
    <title>fkie_cve-2019-16370</title>
    <updated>2026-10-10T18:56:22.748820+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-16370"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hhr2-f668-ff2w</id>
    <title>GHSA-hhr2-f668-ff2w — Use of a weak cryptographic algorithm in Gradle</title>
    <updated>2026-10-10T18:56:22.748852+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.gradle:gradle-core</p>
<p>The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hhr2-f668-ff2w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-16370</id>
    <title>gsd-2019-16370</title>
    <updated>2026-10-10T18:56:22.748878+00:00</updated>
    <content>gsd-2019-16370</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-16370"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1309</id>
    <title>OESA-2021-1309 — gradle security update</title>
    <updated>2026-10-10T18:56:22.748890+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: gradle, openEuler:20.03-LTS-SP2: gradle</p>
<p>Gradle is build automation evolved. Gradle can automate the building, testing, publishing, deployment and more of software packages or other types of projects such as generated static websites, generated documentation or indeed anything else. Gradle combines the power and flexibility of Ant with the dependency management and conventions of Maven into a more effective way to build. Powered by a Groovy DSL and packed with innovation, Gradle provides a declarative way to describe all kinds of builds through sensible defaults. Gradle is quickly becoming the build system of choice for many open source projects, leading edge enterprises and legacy automation challenges.

Security Fix(es):

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.(CVE-2019-16370)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1309"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10817-1</id>
    <title>openSUSE-SU-2024:10817-1 — gradle-4.4.1-7.2 on GA media</title>
    <updated>2026-10-10T18:56:22.748917+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gradle-4.4.1-7.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10817-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16370</id>
    <title>UBUNTU-CVE-2019-16370</title>
    <updated>2026-10-10T18:56:22.748934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: gradle, Ubuntu:Pro:18.04:LTS: gradle, Ubuntu:20.04:LTS: gradle, Ubuntu:22.04:LTS: gradle, Ubuntu:24.04:LTS: gradle, Ubuntu:25.10: gradle, Ubuntu:26.04:LTS: gradle</p>
<p>The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16370"/>
  </entry>
</feed>
