<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:09:52.761116+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-02220</id>
    <title>bdu:2021-02220</title>
    <updated>2026-10-03T15:09:53.217583+00:00</updated>
    <content>bdu:2021-02220</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-02220"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-474</id>
    <title>certfr-2021-avi-474 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T15:09:53.217638+00:00</updated>
    <content>certfr-2021-avi-474</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-30583</id>
    <title>cnvd-2021-30583</title>
    <updated>2026-10-03T15:09:53.217658+00:00</updated>
    <content>cnvd-2021-30583</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-30583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-26327</id>
    <title>EUVD-2026-26327</title>
    <updated>2026-10-03T15:09:53.217671+00:00</updated>
    <content>EUVD-2026-26327</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-26327"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-29425</id>
    <title>fkie_cve-2021-29425</title>
    <updated>2026-10-03T15:09:53.217681+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-29425"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gwrp-pvrq-jmwv</id>
    <title>GHSA-gwrp-pvrq-jmwv — Path Traversal and Improper Input Validation in Apache Commons IO</title>
    <updated>2026-10-03T15:09:53.217711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: commons-io:commons-io, Maven: com.cosium.vet:vet, Maven: com.diamondq.common:common-thirdparty.jcasbin, Maven: com.liferay:com.liferay.sass.compiler.jsass, Maven: com.virjar:ratel-api, Maven: net.hasor:cobble-lang, Maven: org.apache.commons:commons-io, Maven: org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-io, Maven: org.checkerframework.annotatedlib:commons-io, Maven: org.smartboot.servlet:servlet-core</p>
<p>In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gwrp-pvrq-jmwv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-29425</id>
    <title>gsd-2021-29425</title>
    <updated>2026-10-03T15:09:53.217753+00:00</updated>
    <content>gsd-2021-29425</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-29425"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1182</id>
    <title>OESA-2021-1182 — apache-commons-io security update</title>
    <updated>2026-10-03T15:09:53.217766+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: apache-commons-io</p>
<p>Apache commons IO library is used for developing IO functionality. It contains a collecton of utilities with utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more.</p>
<p>Security Fix(es):</p>
<p>In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like //../foo , or .. foo , the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus limited path traversal), if the calling code would use the result to construct a path value.(CVE-2021-29425)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1182"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0605-1</id>
    <title>openSUSE-SU-2021:0605-1 — Security update for apache-commons-io</title>
    <updated>2026-10-03T15:09:53.217791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache-commons-io</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0605-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:2465</id>
    <title>RHSA-2021:2465 — Red Hat Security Advisory: Red Hat build of Eclipse Vert.x 4.1.0 security update</title>
    <updated>2026-10-03T15:09:53.217809+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty: Request smuggling via content-length header apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:2465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:1282-1</id>
    <title>SUSE-SU-2021:1282-1 — Security update for apache-commons-io</title>
    <updated>2026-10-03T15:09:53.217827+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache-commons-io</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:1282-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-29425</id>
    <title>UBUNTU-CVE-2021-29425</title>
    <updated>2026-10-03T15:09:53.217841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: commons-io, Ubuntu:Pro:16.04:LTS: commons-io, Ubuntu:18.04:LTS: commons-io, Ubuntu:20.04:LTS: commons-io</p>
<p>In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-29425"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0119</id>
    <title>WID-SEC-W-2023-0119 — Oracle Utilities Applications: Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:09:53.217865+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Utilities Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0119"/>
  </entry>
</feed>
