<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:33:27.436732+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05507</id>
    <title>bdu:2022-05507</title>
    <updated>2026-10-02T16:33:27.620090+00:00</updated>
    <content>bdu:2022-05507</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05507"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-jenkins-2021-28165</id>
    <title>BIT-jenkins-2021-28165</title>
    <updated>2026-10-02T16:33:27.620137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: jenkins</p>
<p>In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-jenkins-2021-28165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-912</id>
    <title>certfr-2021-avi-912 — De multiples vulnérabilités ont été découvertes dans IBM Qradar.
Certaines d'entre elles permettent à un attaquant de p…</title>
    <updated>2026-10-02T16:33:27.620168+00:00</updated>
    <content>certfr-2021-avi-912</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-25683</id>
    <title>cnvd-2021-25683</title>
    <updated>2026-10-02T16:33:27.620186+00:00</updated>
    <content>cnvd-2021-25683</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-25683"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-251100</id>
    <title>EUVD-2026-251100</title>
    <updated>2026-10-02T16:33:27.620199+00:00</updated>
    <content>EUVD-2026-251100</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-251100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28165</id>
    <title>fkie_cve-2021-28165</title>
    <updated>2026-10-02T16:33:27.620210+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-28165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-26vr-8j45-3r4w</id>
    <title>GHSA-26vr-8j45-3r4w — Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources</title>
    <updated>2026-10-02T16:33:27.620230+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.eclipse.jetty:jetty-server</p>
<p>### Impact
When using SSL/TLS with Jetty, either with HTTP/1.1, HTTP/2, or WebSocket, the server may receive an invalid large (greater than 17408) TLS frame that is incorrectly handled, causing CPU resources to eventually reach 100% usage.</p>
<p>### Workarounds</p>
<p>The problem can be worked around by compiling the following class:
```java
package org.eclipse.jetty.server.ssl.fix6072;</p>
<p>import java.nio.ByteBuffer;
import javax.net.ssl.SSLEngine;
import javax.net.ssl.SSLEngineResult;
import javax.net.ssl.SSLException;
import javax.net.ssl.SSLHandshakeException;</p>
<p>import org.eclipse.jetty.io.EndPoint;
import org.eclipse.jetty.io.ssl.SslConnection;
import org.eclipse.jetty.server.Connector;
import org.eclipse.jetty.server.SslConnectionFactory;
import org.eclipse.jetty.util.BufferUtil;
import org.eclipse.jetty.util.annotation.Name;
import org.eclipse.jetty.util.ssl.SslContextFactory;</p>
<p>public class SpaceCheckingSslConnectionFactory extends SslConnectionFactory
{
    public SpaceCheckingSslConnectionFactory(@Name("sslContextFactory") SslContextFactory factory, @Name("next") String nextProtocol)
    {
        super(factory, nextProtocol);
    }</p>
<p>@Override
    protected SslConnection newSslConnection(Connector connector, EndPoint endPoint, SSLEngine engine)
    {
        return new SslConnection(connector.getByteBufferPool(), connector.getExecutor(), endPoint, engine, isDirectBuffersForEncryption(), isDirectBuffersForDecryption())
        {
            @Override
            protected SSLEn…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-26vr-8j45-3r4w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-28165</id>
    <title>gsd-2021-28165</title>
    <updated>2026-10-02T16:33:27.620284+00:00</updated>
    <content>gsd-2021-28165</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-28165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsma-24-200-01</id>
    <title>ICSMA-24-200-01 — Philips Vue PACS (Update A)</title>
    <updated>2026-10-02T16:33:27.620297+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Attackers can exploit this vulnerability by making numerous requests or sending large amounts of data to the application, leading to resource exhaustion (e.g., memory, CPU), which can cause the application to crash or become unresponsive. This vulnerability does not expose patient data or allow for its modification. It allows an attacker, with access to the hospital's private network, which is protected by security controls (e.g., firewalls, VPNs), to send messages to the server, leading to potential CPU overload and a denial-of-service (DoS) condition. No response is sent back to the attacker, and patient information remains secure. The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and data integrity.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsma-24-200-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1166</id>
    <title>OESA-2021-1166 — jetty security update</title>
    <updated>2026-10-02T16:33:27.620322+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: jetty</p>
<p>%global desc \ Jetty is a 100% Java HTTP Server and Servlet Container. This means that you\ do not need to configure and run a separate web server (like Apache) in order\ to use Java, servlets and JSPs to generate dynamic content. Jetty is a fully\ featured web server for static and dynamic content. Unlike separate\ server/container solutions, this means that your web server and web\ application run in the same process, without interconnection overheads\ and complications. Furthermore, as a pure java component, Jetty can be simply\ included in your application for demonstration, distribution or deployment.\ Jetty is available on all Java supported platforms. %{desc} %global extdesc %{desc}\ \ This package contains

Security Fix(es):

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.(CVE-2020-27223)

In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.(CVE-2021-28165)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:2005-1</id>
    <title>openSUSE-SU-2021:2005-1 — Security update for jetty-minimal</title>
    <updated>2026-10-02T16:33:27.620352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jetty-minimal</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:2005-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:1509</id>
    <title>RHSA-2021:1509 — Red Hat Security Advisory: rh-eclipse-jetty security update</title>
    <updated>2026-10-02T16:33:27.620370+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:1509"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:2005-1</id>
    <title>SUSE-SU-2021:2005-1 — Security update for jetty-minimal</title>
    <updated>2026-10-02T16:33:27.620389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jetty-minimal</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:2005-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28165</id>
    <title>UBUNTU-CVE-2021-28165</title>
    <updated>2026-10-02T16:33:27.620404+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: equinox-bundles, Ubuntu:20.04:LTS: equinox-bundles, Ubuntu:22.04:LTS: equinox-bundles</p>
<p>In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1365</id>
    <title>WID-SEC-W-2022-1365 — Eclipse Jetty: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:33:27.620426+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um Informationen offenzulegen und einen Denial of Service Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1365"/>
  </entry>
</feed>
