<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:21:19.181198+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-44531</id>
    <title>cnvd-2019-44531</title>
    <updated>2026-10-03T04:21:19.265742+00:00</updated>
    <content>cnvd-2019-44531</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-44531"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-49759</id>
    <title>EUVD-2026-49759</title>
    <updated>2026-10-03T04:21:19.265777+00:00</updated>
    <content>EUVD-2026-49759</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-49759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-3875</id>
    <title>fkie_cve-2019-3875</title>
    <updated>2026-10-03T04:21:19.265791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ('http' or 'ldap') and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn't validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-3875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-38cg-gg9j-q9j9</id>
    <title>GHSA-38cg-gg9j-q9j9 — Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak</title>
    <updated>2026-10-03T04:21:19.265823+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-core</p>
<p>A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ('http' or 'ldap') and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn't validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-38cg-gg9j-q9j9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-3875</id>
    <title>gsd-2019-3875</title>
    <updated>2026-10-03T04:21:19.265850+00:00</updated>
    <content>gsd-2019-3875</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-3875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:1456</id>
    <title>RHSA-2019:1456 — Red Hat Security Advisory: Red Hat Single Sign-On 7.3.2 security update</title>
    <updated>2026-10-03T04:21:19.265862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bootstrap: XSS in the data-target attribute bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy bootstrap: XSS in the tooltip data-viewport attribute bootstrap: XSS in the affix configuration target property picketlink: reflected XSS in SAMLRequest via RelayState parameter picketlink: URL injection via xinclude parameter keycloak: missing signatures validation on CRL used to verify client certificates undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailed bootstrap: XSS in the tooltip or popover data-template attribute keycloak: Node.js adapter internal NBF can be manipulated leading to DoS. jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:1456"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1947</id>
    <title>WID-SEC-W-2022-1947 — Red Hat Single Sign On: Mehrere Schwachstellen</title>
    <updated>2026-10-03T04:21:19.265891+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein  Angreifer kann mehrere Schwachstellen in Red Hat Single Sign On ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, einen Denial of Service Zustand hervorzurufen, Informationen auszuspähen, Sicherheitsvorkehrungen zu umgehen oder beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1947"/>
  </entry>
</feed>
