<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:14:40.718767+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-04263</id>
    <title>bdu:2025-04263</title>
    <updated>2026-10-03T23:14:40.851304+00:00</updated>
    <content>bdu:2025-04263</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-04263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</id>
    <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T23:14:40.851359+00:00</updated>
    <content>certfr-2026-avi-1165</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-46248</id>
    <title>EUVD-2026-46248</title>
    <updated>2026-10-03T23:14:40.851399+00:00</updated>
    <content>EUVD-2026-46248</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-46248"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-26945</id>
    <title>fkie_cve-2020-26945</title>
    <updated>2026-10-03T23:14:40.851428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MyBatis before 3.5.6 mishandles deserialization of object streams.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-26945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qq48-m4jx-xqh8</id>
    <title>GHSA-qq48-m4jx-xqh8 — "Deserialization errors in MyBatis"</title>
    <updated>2026-10-03T23:14:40.851479+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.mybatis:mybatis</p>
<p>MyBatis before 3.5.6 mishandles deserialization of object streams leading to potential cache poisoning.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qq48-m4jx-xqh8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-26945</id>
    <title>gsd-2020-26945</title>
    <updated>2026-10-03T23:14:40.851541+00:00</updated>
    <content>gsd-2020-26945</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-26945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1292</id>
    <title>OESA-2021-1292 — mybatis security update</title>
    <updated>2026-10-03T23:14:40.851569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP2: mybatis</p>
<p>The MyBatis data mapper framework makes it easier to use a relational database with object-oriented applications. MyBatis couples objects with stored procedures or SQL statements using a XML descriptor or annotations. Simplicity is the biggest advantage of the MyBatis data mapper over object relational mapping tools. To use the MyBatis data mapper, you rely on your own objects, XML, and SQL. There is little to learn that you don&amp;apos;t already know. With the MyBatis data mapper, you have the full power of both SQL and stored procedures at your fingertips. The MyBatis project is developed and maintained by a team that includes the original creators of the &amp;quot;iBATIS&amp;quot; data mapper. The Apache project was retired and continued here.

Security Fix(es):

MyBatis before 3.5.6 mishandles deserialization of object streams.(CVE-2020-26945)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1292"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11070-1</id>
    <title>openSUSE-SU-2024:11070-1 — mybatis-3.5.6-1.6 on GA media</title>
    <updated>2026-10-03T23:14:40.851636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mybatis-3.5.6-1.6 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11070-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:3140</id>
    <title>RHSA-2021:3140 — Red Hat Security Advisory: Red Hat Fuse 7.9.0 release and security update</title>
    <updated>2026-10-03T23:14:40.851676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>log4j: Socket receiver deserialization vulnerability snakeyaml: Billion laughs attack via alias feature apache-commons-compress: Infinite loop in name encoding algorithm wildfly: The 'enabled-protocols' value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class olingo-odata: Server side request forgery in AsyncResponseWrapperImpl tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability spring-cloud-config-server: sending a request using a specially crafted URL can lead to a directory traversal attack springframework: RFD protection bypass via jsessionid Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 tomcat: deserialization flaw in session persistence storage leading to RCE RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack hibernate-validator: Improper input validation in the interpolation of constraint error messages wildfly-elytron: session fixation when using FORM authentication undertow: invalid HTTP request with large chunk size tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:3140"/>
  </entry>
</feed>
