<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:33:12.836655+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00046</id>
    <title>bdu:2024-00046</title>
    <updated>2026-10-04T01:33:13.064971+00:00</updated>
    <content>bdu:2024-00046</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00046"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-kafka-2021-38153</id>
    <title>BIT-kafka-2021-38153 — Timing Attack Vulnerability for Apache Kafka Connect and Clients</title>
    <updated>2026-10-04T01:33:13.065011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: kafka</p>
<p>Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-kafka-2021-38153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-568</id>
    <title>certfr-2022-avi-568 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T01:33:13.065051+00:00</updated>
    <content>certfr-2022-avi-568</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-568"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-14712</id>
    <title>cnvd-2022-14712</title>
    <updated>2026-10-04T01:33:13.065075+00:00</updated>
    <content>cnvd-2022-14712</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-14712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-30175</id>
    <title>EUVD-2026-30175</title>
    <updated>2026-10-04T01:33:13.065089+00:00</updated>
    <content>EUVD-2026-30175</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-30175"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-38153</id>
    <title>fkie_cve-2021-38153</title>
    <updated>2026-10-04T01:33:13.065099+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-38153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3j6g-hxx5-3q26</id>
    <title>GHSA-3j6g-hxx5-3q26 — Observable Discrepancy in Apache Kafka</title>
    <updated>2026-10-04T01:33:13.065128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.kafka:kafka_2.11, Maven: org.apache.kafka:kafka_2.12, Maven: org.apache.kafka:kafka_2.13, Maven: org.apache.kafka:kafka-clients</p>
<p>Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3j6g-hxx5-3q26"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-38153</id>
    <title>gsd-2021-38153</title>
    <updated>2026-10-04T01:33:13.065185+00:00</updated>
    <content>gsd-2021-38153</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-38153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:0138</id>
    <title>RHSA-2022:0138 — Red Hat Security Advisory: Red Hat AMQ Streams 2.0.0 release and security update</title>
    <updated>2026-10-04T01:33:13.065202+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jetty: crafted URIs allow bypassing security constraints netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients log4j-core: remote code execution via JDBC Appender log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:0138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38153</id>
    <title>UBUNTU-CVE-2021-38153</title>
    <updated>2026-10-04T01:33:13.065244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: kafka</p>
<p>Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</id>
    <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:33:13.065276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607"/>
  </entry>
</feed>
