<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:38:00.346132+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-36236</id>
    <title>cnvd-2020-36236</title>
    <updated>2026-10-02T22:38:00.606572+00:00</updated>
    <content>cnvd-2020-36236</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-36236"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-40001</id>
    <title>EUVD-2026-40001</title>
    <updated>2026-10-02T22:38:00.606642+00:00</updated>
    <content>EUVD-2026-40001</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-40001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10705</id>
    <title>fkie_cve-2020-10705</title>
    <updated>2026-10-02T22:38:00.606662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-10705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g4cp-h53p-v3v8</id>
    <title>GHSA-g4cp-h53p-v3v8 — Allocation of Resources Without Limits or Throttling in Undertow</title>
    <updated>2026-10-02T22:38:00.606707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.undertow:undertow-core</p>
<p>A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g4cp-h53p-v3v8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-10705</id>
    <title>gsd-2020-10705</title>
    <updated>2026-10-02T22:38:00.606735+00:00</updated>
    <content>gsd-2020-10705</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-10705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1422</id>
    <title>OESA-2021-1422 — undertow security update</title>
    <updated>2026-10-02T22:38:00.606748+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: undertow, openEuler:20.03-LTS-SP2: undertow</p>
<p>Java web server using non-blocking IO

Security Fix(es):

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)(CVE-2019-3888)

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the &amp;quot;Expect: 100-continue&amp;quot; header may cause an out of memory error. This flaw may potentially lead to a denial of service.(CVE-2020-10705)

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.(CVE-2020-10719)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1422"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:2058</id>
    <title>RHSA-2020:2058 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.8 on RHEL 6 security update</title>
    <updated>2026-10-02T22:38:00.606777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-mapper-asl: XML external entity similar to CVE-2016-3720 cxf: OpenId Connect token service does not properly validate the clientId cxf: reflected XSS in the services listing page Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader Soteria: security identity corruption across concurrent threads undertow: AJP File Read/Inclusion Vulnerability undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass cryptacular: excessive memory allocation during a decode operation undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header undertow: invalid HTTP request with large chunk size</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:2058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10705</id>
    <title>UBUNTU-CVE-2020-10705</title>
    <updated>2026-10-02T22:38:00.606817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:Pro:20.04:LTS: undertow, Ubuntu:Pro:22.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow</p>
<p>A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2123</id>
    <title>WID-SEC-W-2025-2123 — Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:38:00.606848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Angriff durchzuführen, einen Denial of Service Zustand herbeizuführen, Informationen offenzulegen oder Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2123"/>
  </entry>
</feed>
