<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:33:49.887033+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01096</id>
    <title>bdu:2024-01096</title>
    <updated>2026-10-03T19:33:49.930351+00:00</updated>
    <content>bdu:2024-01096</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-41082</id>
    <title>cnvd-2020-41082</title>
    <updated>2026-10-03T19:33:49.930405+00:00</updated>
    <content>cnvd-2020-41082</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-41082"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-39998</id>
    <title>EUVD-2026-39998</title>
    <updated>2026-10-03T19:33:49.930421+00:00</updated>
    <content>EUVD-2026-39998</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-39998"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10688</id>
    <title>fkie_cve-2020-10688</title>
    <updated>2026-10-03T19:33:49.930434+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-10688"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-29qj-rvv6-qrmv</id>
    <title>GHSA-29qj-rvv6-qrmv — Cross-site scripting in RESTEasy</title>
    <updated>2026-10-03T19:33:49.930491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jboss.resteasy:resteasy-bom, Maven: org.jboss.resteasy:resteasy-core</p>
<p>A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-29qj-rvv6-qrmv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-10688</id>
    <title>gsd-2020-10688</title>
    <updated>2026-10-03T19:33:49.930533+00:00</updated>
    <content>gsd-2020-10688</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-10688"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1231</id>
    <title>OESA-2021-1231 — resteasy security update</title>
    <updated>2026-10-03T19:33:49.930545+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: resteasy</p>
<p>%global desc \ RESTEasy contains a JBoss project that provides frameworks to help\ build RESTful Web Services and RESTful Java applications. It is a fully\ certified and portable implementation of the JAX-RS specification. \ %global extdesc \\ \ This package contains

Security Fix(es):

A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.(CVE-2020-10688)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1231"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:2333</id>
    <title>RHSA-2020:2333 — Red Hat Security Advisory: EAP Continuous Delivery Technical Preview Release 19 security update</title>
    <updated>2026-10-03T19:33:49.930567+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods cxf: OpenId Connect token service does not properly validate the clientId cxf: OpenId Connect token service does not properly validate the clientId jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig wildfly: The 'enabled-protocols' value in legacy security is not respected if OpenSSL security provider is in use undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS jackson-databind: Serialization gadgets in classes of the commons-configuration package jackson-databind: Serialization gadgets in classes of the xalan package jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in classes of the ehcache package jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.* cxf: reflected XSS in the services listing page jackson-databind: lacks certain net.sf.ehcache blocking netty: HTTP reque…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:2333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10688</id>
    <title>UBUNTU-CVE-2020-10688</title>
    <updated>2026-10-03T19:33:49.930646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: resteasy, Ubuntu:Pro:18.04:LTS: resteasy3.0, Ubuntu:Pro:20.04:LTS: resteasy, Ubuntu:Pro:20.04:LTS: resteasy3.0, Ubuntu:22.04:LTS: resteasy3.0, Ubuntu:Pro:22.04:LTS: resteasy, Ubuntu:Pro:24.04:LTS: resteasy, Ubuntu:25.10: resteasy, Ubuntu:26.04:LTS: resteasy</p>
<p>A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10688"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2050</id>
    <title>WID-SEC-W-2022-2050 — Red Hat JBoss Application Server (JBoss): Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:33:49.930677+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat JBoss Application Server (JBoss) ausnutzen, um Informationen offenzulegen, Daten zu manipulieren oder einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2050"/>
  </entry>
</feed>
