<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:45:30.869647+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05510</id>
    <title>bdu:2022-05510</title>
    <updated>2026-10-04T02:45:31.076954+00:00</updated>
    <content>bdu:2022-05510</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-951</id>
    <title>certfr-2021-avi-951 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-04T02:45:31.077005+00:00</updated>
    <content>certfr-2021-avi-951</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-951"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-27374</id>
    <title>cnvd-2021-27374</title>
    <updated>2026-10-04T02:45:31.077024+00:00</updated>
    <content>cnvd-2021-27374</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-27374"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-25867</id>
    <title>EUVD-2026-25867</title>
    <updated>2026-10-04T02:45:31.077036+00:00</updated>
    <content>EUVD-2026-25867</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-25867"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28164</id>
    <title>fkie_cve-2021-28164</title>
    <updated>2026-10-04T02:45:31.077047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-28164"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v7ff-8wcx-gmc5</id>
    <title>GHSA-v7ff-8wcx-gmc5 — Authorization Before Parsing and Canonicalization in jetty</title>
    <updated>2026-10-04T02:45:31.077075+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.eclipse.jetty:jetty-webapp</p>
<p>Release 9.4.37 introduced a more precise implementation of [RFC3986](https://tools.ietf.org/html/rfc3986#section-3.3) with regards to URI decoding, together with some new compliance modes to optionally allow support of some URI that may have ambiguous interpretation within the Servlet specified API methods behaviours.   The default mode allowed % encoded . characters to be excluded for URI normalisation, which is correct by the RFC, but is not assumed by common Servlet implementations. The default compliance mode allows requests with URIs that contain `%2e` or `%2e%2e` segments to access protected resources within the `WEB-INF` directory.  For example a request to `/context/%2e/WEB-INF/web.xml` can retrieve the `web.xml` file.  This can reveal sensitive information regarding the implementation of a web application. Workarounds found by HttpCompliance mode RFC7230_NO_AMBIGUOUS_URIS can be enabled by updating `start.d/http.ini` to include: jetty.http.compliance=RFC7230_NO_AMBIGUOUS_URIS.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v7ff-8wcx-gmc5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-28164</id>
    <title>gsd-2021-28164</title>
    <updated>2026-10-04T02:45:31.077103+00:00</updated>
    <content>gsd-2021-28164</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-28164"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:2005-1</id>
    <title>openSUSE-SU-2021:2005-1 — Security update for jetty-minimal</title>
    <updated>2026-10-04T02:45:31.077115+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jetty-minimal</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:2005-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:1509</id>
    <title>RHSA-2021:1509 — Red Hat Security Advisory: rh-eclipse-jetty security update</title>
    <updated>2026-10-04T02:45:31.077134+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:1509"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:2005-1</id>
    <title>SUSE-SU-2021:2005-1 — Security update for jetty-minimal</title>
    <updated>2026-10-04T02:45:31.077152+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jetty-minimal</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:2005-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28164</id>
    <title>UBUNTU-CVE-2021-28164</title>
    <updated>2026-10-04T02:45:31.077168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: equinox-bundles, Ubuntu:20.04:LTS: equinox-bundles, Ubuntu:22.04:LTS: equinox-bundles</p>
<p>In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28164"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1365</id>
    <title>WID-SEC-W-2022-1365 — Eclipse Jetty: Mehrere Schwachstellen</title>
    <updated>2026-10-04T02:45:31.077191+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um Informationen offenzulegen und einen Denial of Service Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1365"/>
  </entry>
</feed>
