<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:05:03.998794+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-05588</id>
    <title>bdu:2021-05588</title>
    <updated>2026-10-02T22:05:04.005758+00:00</updated>
    <content>bdu:2021-05588</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-05588"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-88202</id>
    <title>cnvd-2021-88202</title>
    <updated>2026-10-02T22:05:04.005791+00:00</updated>
    <content>cnvd-2021-88202</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-88202"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-31609</id>
    <title>EUVD-2026-31609</title>
    <updated>2026-10-02T22:05:04.005805+00:00</updated>
    <content>EUVD-2026-31609</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-31609"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41269</id>
    <title>fkie_cve-2021-41269</title>
    <updated>2026-10-02T22:05:04.005815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected. The issue was patched and a new version was released. Please upgrade to version 9.1.6. There are no known workarounds known.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-41269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p9m8-27x8-rg87</id>
    <title>GHSA-p9m8-27x8-rg87 — Critical vulnerability found in cron-utils</title>
    <updated>2026-10-02T22:05:04.005844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.cronutils:cron-utils</p>
<p>### Impact
A Template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected.</p>
<p>### Patches
The issue was patched and a new version was released. Please upgrade to version 9.1.6.</p>
<p>### Workarounds
There are no known workarounds up to this moment.</p>
<p>### References
A description of the issue is provided in [issue 461](https://github.com/jmrozanec/cron-utils/issues/461)</p>
<p>### For more information
If you have any questions or comments about this advisory:</p>
<p>Open an issue in the [cron-utils Github repository](https://github.com/jmrozanec/cron-utils)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p9m8-27x8-rg87"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-41269</id>
    <title>gsd-2021-41269</title>
    <updated>2026-10-02T22:05:04.005874+00:00</updated>
    <content>gsd-2021-41269</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-41269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:0589</id>
    <title>RHSA-2022:0589 — Red Hat Security Advisory: Red Hat build of Quarkus 2.2.5 release and security update</title>
    <updated>2026-10-02T22:05:04.005886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mysql-connector-java: unauthorized access to critical kubernetes-client: Insecure deserialization in unmarshalYaml method jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients cron-utils: template Injection leading to unauthenticated Remote Code Execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:0589"/>
  </entry>
</feed>
