<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:00:10.576369+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-05622</id>
    <title>bdu:2020-05622</title>
    <updated>2026-10-04T21:00:10.780046+00:00</updated>
    <content>bdu:2020-05622</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-05622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-activemq-2020-26217</id>
    <title>BIT-activemq-2020-26217 — Remote Code Execution in XStream</title>
    <updated>2026-10-04T21:00:10.780089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: activemq</p>
<p>XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-activemq-2020-26217"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-490</id>
    <title>certfr-2021-avi-490 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
Protect. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-04T21:00:10.780126+00:00</updated>
    <content>certfr-2021-avi-490</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-63975</id>
    <title>cnvd-2020-63975</title>
    <updated>2026-10-04T21:00:10.780143+00:00</updated>
    <content>cnvd-2020-63975</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-63975"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-45982</id>
    <title>EUVD-2026-45982</title>
    <updated>2026-10-04T21:00:10.780155+00:00</updated>
    <content>EUVD-2026-45982</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-45982"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-26217</id>
    <title>fkie_cve-2020-26217</title>
    <updated>2026-10-04T21:00:10.780165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-26217"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mw36-7c6c-q4q2</id>
    <title>GHSA-mw36-7c6c-q4q2 — XStream can be used for Remote Code Execution</title>
    <updated>2026-10-04T21:00:10.780188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.thoughtworks.xstream:xstream</p>
<p>### Impact
The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream.</p>
<p>### Patches
If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.14.</p>
<p>### Workarounds
No user is affected, who followed the recommendation to setup XStream's Security Framework with a whitelist! Anyone relying on XStream's default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability.</p>
<p>Users of XStream 1.4.13 or below who still want to use XStream default blacklist can use a workaround depending on their version in use.</p>
<p>Users of XStream 1.4.13 can simply add two lines to XStream's setup code:
```Java
xstream.denyTypes(new String[]{ "javax.imageio.ImageIO$ContainsFilter" });
xstream.denyTypes(new Class[]{ java.lang.ProcessBuilder.class });
```
Users of XStream 1.4.12 to 1.4.7 who want to use XStream with a black list will have to setup such a list from scratch and deny at least the following types: _javax.imageio.ImageIO$ContainsFilter_, _java.beans.EventHandler_, _java.lang.ProcessBuilder_, _java.lang.Void_ and _void_.
```Java
xstream.denyTypes(new String[]{ "javax.imageio.ImageIO$ContainsFilter" });
xstream.denyTypes(new Class[]{ java.lang.ProcessBuilder.class, java.beans.EventHandler.class, java.lang.ProcessBuilder.class, java.lang.Void.class, void.class });
```
Users of XStream 1.4…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mw36-7c6c-q4q2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-26217</id>
    <title>gsd-2020-26217</title>
    <updated>2026-10-04T21:00:10.780233+00:00</updated>
    <content>gsd-2020-26217</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-26217"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0140-1</id>
    <title>openSUSE-SU-2021:0140-1 — Security update for xstream</title>
    <updated>2026-10-04T21:00:10.780245+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for xstream</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0140-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0105</id>
    <title>RHSA-2021:0105 — Red Hat Security Advisory: Red Hat Process Automation Manager 7.9.1 security update</title>
    <updated>2026-10-04T21:00:10.780264+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XStream: remote code execution due to insecure XML deserialization when relying on blocklists</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0105"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:0176-1</id>
    <title>SUSE-SU-2021:0176-1 — Security update for xstream</title>
    <updated>2026-10-04T21:00:10.780279+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for xstream</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:0176-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-26217</id>
    <title>UBUNTU-CVE-2020-26217</title>
    <updated>2026-10-04T21:00:10.780293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libxstream-java, Ubuntu:Pro:16.04:LTS: libxstream-java, Ubuntu:18.04:LTS: libxstream-java, Ubuntu:20.04:LTS: libxstream-java</p>
<p>XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-26217"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0094</id>
    <title>WID-SEC-W-2024-0094 — Atlassian Bamboo: Mehrere Schwachstellen</title>
    <updated>2026-10-04T21:00:10.780318+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Atlassian Bamboo ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen oder einen Request Smuggling-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0094"/>
  </entry>
</feed>
