<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:35:02.595099+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-04803</id>
    <title>bdu:2020-04803</title>
    <updated>2026-10-03T05:35:02.895798+00:00</updated>
    <content>bdu:2020-04803</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-04803"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-03215</id>
    <title>cnvd-2020-03215</title>
    <updated>2026-10-03T05:35:02.895847+00:00</updated>
    <content>cnvd-2020-03215</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-03215"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-49787</id>
    <title>EUVD-2026-49787</title>
    <updated>2026-10-03T05:35:02.895863+00:00</updated>
    <content>EUVD-2026-49787</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-49787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-3888</id>
    <title>fkie_cve-2019-3888</title>
    <updated>2026-10-03T05:35:02.895875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-3888"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jwgx-9mmh-684w</id>
    <title>GHSA-jwgx-9mmh-684w — Credential exposure through log files in Undertow</title>
    <updated>2026-10-03T05:35:02.895907+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.undertow:undertow-core</p>
<p>A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jwgx-9mmh-684w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-3888</id>
    <title>gsd-2019-3888</title>
    <updated>2026-10-03T05:35:02.895951+00:00</updated>
    <content>gsd-2019-3888</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-3888"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1422</id>
    <title>OESA-2021-1422 — undertow security update</title>
    <updated>2026-10-03T05:35:02.895971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: undertow, openEuler:20.03-LTS-SP2: undertow</p>
<p>Java web server using non-blocking IO

Security Fix(es):

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)(CVE-2019-3888)

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the &amp;quot;Expect: 100-continue&amp;quot; header may cause an out of memory error. This flaw may potentially lead to a denial of service.(CVE-2020-10705)

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.(CVE-2020-10719)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1422"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:1419</id>
    <title>RHSA-2019:1419 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.2 on RHEL 6 security update</title>
    <updated>2026-10-03T05:35:02.896023+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>picketlink: reflected XSS in SAMLRequest via RelayState parameter picketlink: URL injection via xinclude parameter undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailed</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:1419"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-3888</id>
    <title>UBUNTU-CVE-2019-3888</title>
    <updated>2026-10-03T05:35:02.896060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:20.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow</p>
<p>A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-3888"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1947</id>
    <title>WID-SEC-W-2022-1947 — Red Hat Single Sign On: Mehrere Schwachstellen</title>
    <updated>2026-10-03T05:35:02.896114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein  Angreifer kann mehrere Schwachstellen in Red Hat Single Sign On ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, einen Denial of Service Zustand hervorzurufen, Informationen auszuspähen, Sicherheitsvorkehrungen zu umgehen oder beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1947"/>
  </entry>
</feed>
