<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:32:42.064190+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05216</id>
    <title>bdu:2023-05216</title>
    <updated>2026-10-03T19:32:42.340860+00:00</updated>
    <content>bdu:2023-05216</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05216"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-26291</id>
    <title>Withdrawn: BELL-CVE-2021-26291 — CVE-2021-26291 does not affect BellSoft software</title>
    <updated>2026-10-03T19:32:42.340903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-26291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-maven-2021-26291</id>
    <title>BIT-maven-2021-26291 — block repositories using http by default</title>
    <updated>2026-10-03T19:32:42.340923+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: maven</p>
<p>Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-maven-2021-26291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-659</id>
    <title>certfr-2022-avi-659 — De multiples vulnérabilités ont été découvertes dans Oracle WebLogic.
Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-03T19:32:42.340961+00:00</updated>
    <content>certfr-2022-avi-659</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-36229</id>
    <title>cnvd-2021-36229</title>
    <updated>2026-10-03T19:32:42.340978+00:00</updated>
    <content>cnvd-2021-36229</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-36229"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-24986</id>
    <title>EUVD-2026-24986</title>
    <updated>2026-10-03T19:32:42.340989+00:00</updated>
    <content>EUVD-2026-24986</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-24986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-26291</id>
    <title>fkie_cve-2021-26291</title>
    <updated>2026-10-03T19:32:42.340999+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-26291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2f88-5hg8-9x2x</id>
    <title>GHSA-2f88-5hg8-9x2x — Origin Validation Error in Apache Maven</title>
    <updated>2026-10-03T19:32:42.341024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.maven:maven-compat, Maven: org.apache.maven:maven-core</p>
<p>Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2f88-5hg8-9x2x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-26291</id>
    <title>gsd-2021-26291</title>
    <updated>2026-10-03T19:32:42.341052+00:00</updated>
    <content>gsd-2021-26291</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-26291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-26291</id>
    <title>msrc_CVE-2021-26291 — block repositories using http by default</title>
    <updated>2026-10-03T19:32:42.341064+00:00</updated>
    <content>msrc_CVE-2021-26291</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-26291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1276</id>
    <title>OESA-2021-1276 — maven security update</title>
    <updated>2026-10-03T19:32:42.341079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: maven, openEuler:20.03-LTS-SP2: maven</p>
<p>Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project&amp;apos;s build, reporting and documentation from a central piece of information.

Security Fix(es):

Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html(CVE-2021-26291)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10687-1</id>
    <title>openSUSE-SU-2024:10687-1 — clojure-1.10.3.855-1.2 on GA media</title>
    <updated>2026-10-03T19:32:42.341109+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>clojure-1.10.3.855-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10687-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:3880</id>
    <title>RHSA-2021:3880 — Red Hat Security Advisory: Red Hat build of Quarkus 2.2.3 release and security update</title>
    <updated>2026-10-03T19:32:42.341126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception wildfly-elytron: possible timing attack in ScramServer resteasy: Error message exposes endpoint class information netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation netty: Request smuggling via content-length header maven: Block repositories using http by default</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:3880"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-26291</id>
    <title>UBUNTU-CVE-2021-26291</title>
    <updated>2026-10-03T19:32:42.341150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: maven, Ubuntu:Pro:16.04:LTS: maven, Ubuntu:Pro:18.04:LTS: maven, Ubuntu:Pro:20.04:LTS: maven, Ubuntu:Pro:22.04:LTS: maven</p>
<p>Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-26291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</id>
    <title>WID-SEC-W-2022-1375 — JFrog Artifactory: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:32:42.341181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375"/>
  </entry>
</feed>
