<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:45:13.481431+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-04938</id>
    <title>bdu:2020-04938</title>
    <updated>2026-10-04T08:45:13.715976+00:00</updated>
    <content>bdu:2020-04938</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-04938"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-tomcat-2020-13935</id>
    <title>BIT-tomcat-2020-13935</title>
    <updated>2026-10-04T08:45:13.716023+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: tomcat</p>
<p>The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 9.0.0 through 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-tomcat-2020-13935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-626</id>
    <title>certfr-2020-avi-626 — De multiples vulnérabilités ont été découvertes dans Apache Tomcat.
Elles permettent à un attaquant de provoquer un dén…</title>
    <updated>2026-10-04T08:45:13.716057+00:00</updated>
    <content>certfr-2020-avi-626</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-46230</id>
    <title>cnvd-2020-46230</title>
    <updated>2026-10-04T08:45:13.716074+00:00</updated>
    <content>cnvd-2020-46230</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-46230"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42094</id>
    <title>EUVD-2026-42094</title>
    <updated>2026-10-04T08:45:13.716086+00:00</updated>
    <content>EUVD-2026-42094</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13935</id>
    <title>fkie_cve-2020-13935</title>
    <updated>2026-10-04T08:45:13.716097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-13935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m7jv-hq7h-mq7c</id>
    <title>GHSA-m7jv-hq7h-mq7c — Infinite Loop in Apache Tomcat</title>
    <updated>2026-10-04T08:45:13.716119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat, Maven: org.apache.tomcat.embed:tomcat-embed-websocket, Maven: org.apache.tomcat:tomcat-websocket</p>
<p>The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m7jv-hq7h-mq7c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-13935</id>
    <title>gsd-2020-13935</title>
    <updated>2026-10-04T08:45:13.716151+00:00</updated>
    <content>gsd-2020-13935</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-13935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1102-1</id>
    <title>openSUSE-SU-2020:1102-1 — Security update for tomcat</title>
    <updated>2026-10-04T08:45:13.716163+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1102-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:3303</id>
    <title>RHSA-2020:3303 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 10 security update</title>
    <updated>2026-10-04T08:45:13.716181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:3303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:2037-1</id>
    <title>SUSE-SU-2020:2037-1 — Security update for tomcat</title>
    <updated>2026-10-04T08:45:13.716199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:2037-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13935</id>
    <title>UBUNTU-CVE-2020-13935</title>
    <updated>2026-10-04T08:45:13.716214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: tomcat9</p>
<p>The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0519</id>
    <title>WID-SEC-W-2022-0519 — Apache Tomcat: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-04T08:45:13.716240+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0519"/>
  </entry>
</feed>
