<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T22:30:14.667461+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-32367</id>
    <title>cnvd-2020-32367</title>
    <updated>2026-10-04T22:30:14.736668+00:00</updated>
    <content>cnvd-2020-32367</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-32367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-39990</id>
    <title>EUVD-2026-39990</title>
    <updated>2026-10-04T22:30:14.736726+00:00</updated>
    <content>EUVD-2026-39990</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-39990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10687</id>
    <title>fkie_cve-2020-10687</title>
    <updated>2026-10-04T22:30:14.736742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-10687"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p9w3-gwc2-cr49</id>
    <title>GHSA-p9w3-gwc2-cr49 — HTTP Request Smuggling in Undertow</title>
    <updated>2026-10-04T22:30:14.736774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.undertow:undertow-core</p>
<p>A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p9w3-gwc2-cr49"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-10687</id>
    <title>gsd-2020-10687</title>
    <updated>2026-10-04T22:30:14.736799+00:00</updated>
    <content>gsd-2020-10687</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-10687"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:3192</id>
    <title>RHSA-2020:3192 — Red Hat Security Advisory: Red Hat Fuse 7.7.0 release and security update</title>
    <updated>2026-10-04T22:30:14.736811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl elasticsearch: Information exposure via _cluster/settings API pdfbox: unbounded computation in parser resulting in a denial of service vertx: WebSocket HTTP upgrade implementation holds the entire http request in memory before the handshake dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents mina-core: Retaining an open socket in close_notify SSL-TLS leading to Information disclosure. spring-data-jpa: Additional information exposure with Spring Data JPA derived queries HTTP/2: large amount of data requests leads to denial of service hawtio: server side request forgery via initial /proxy/ substring of a URI apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default jackson-mapper-asl: XML external entity similar to CVE-2016-3720 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server. xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source cxf: OpenId Connect token service does not properly validate the clientId jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS jackson-databind: Serialization gadgets in classes of the commons-configuration package jackson-databind: Serialization gadgets in clas…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:3192"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10687</id>
    <title>UBUNTU-CVE-2020-10687</title>
    <updated>2026-10-04T22:30:14.736896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:Pro:20.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow</p>
<p>A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10687"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1912</id>
    <title>WID-SEC-W-2022-1912 — Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-04T22:30:14.736924+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um Code zur Ausführung zu bringen, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1912"/>
  </entry>
</feed>
