<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:14:29.416693+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05508</id>
    <title>bdu:2022-05508</title>
    <updated>2026-10-03T03:14:29.677707+00:00</updated>
    <content>bdu:2022-05508</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05508"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-jenkins-2021-43859</id>
    <title>BIT-jenkins-2021-43859 — Denial of Service by injecting highly recursive collections or maps in XStream</title>
    <updated>2026-10-03T03:14:29.677790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: jenkins</p>
<p>XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-jenkins-2021-43859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-597</id>
    <title>certfr-2022-avi-597 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
Protect Plus. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-03T03:14:29.677827+00:00</updated>
    <content>certfr-2022-avi-597</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258320</id>
    <title>EUVD-2026-258320</title>
    <updated>2026-10-03T03:14:29.677846+00:00</updated>
    <content>EUVD-2026-258320</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258320"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43859</id>
    <title>fkie_cve-2021-43859</title>
    <updated>2026-10-03T03:14:29.677858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-43859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rmr5-cpv2-vgjf</id>
    <title>GHSA-rmr5-cpv2-vgjf — Denial of Service by injecting highly recursive collections or maps in XStream</title>
    <updated>2026-10-03T03:14:29.677883+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.thoughtworks.xstream:xstream</p>
<p>### Impact
The vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream.</p>
<p>### Patches
XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded.</p>
<p>### Workarounds
The attack uses the hash code implementation for collections and maps to force an exponential calculation time due to highly recursive structures with in the collection or map. Following types of the Java runtime are affected in Java versions available in December 2021:</p>
<p>- java.util.HashMap
- java.util.HashSet
- java.util.Hashtable
- java.util.LinkedHashMap
- java.util.LinkedHashSet
- java.util.Stack (older Java revisions only)
- java.util.Vector (older Java revisions only)
- Other third party collection implementations that use their element's hash code may also be affected</p>
<p>If your object graph does not use referenced elements at all, you may simply set the NO_REFERENCE mode:
```Java
XStream xstream = new XStream();
xstream.setMode(XStream.NO_REFERENCES);
```</p>
<p>If your object graph contains neither a Hashtable, HashMap nor a HashSet (or one of the linked variants of it) then you can use the security framework to deny the usage of these types:
```Java
XStream xstream = new XStream();
xstream.denyTypes(new Class[]{
 java.util.HashMap.class, java.util.HashSet.cl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rmr5-cpv2-vgjf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-43859</id>
    <title>gsd-2021-43859</title>
    <updated>2026-10-03T03:14:29.677925+00:00</updated>
    <content>gsd-2021-43859</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-43859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1512</id>
    <title>OESA-2022-1512 — xstream security update</title>
    <updated>2026-10-03T03:14:29.677938+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: xstream, openEuler:20.03-LTS-SP2: xstream, openEuler:20.03-LTS-SP3: xstream</p>
<p>Java XML serialization library.

Security Fix(es):

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.(CVE-2021-43859)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1512"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0817-1</id>
    <title>openSUSE-SU-2022:0817-1 — Security update for xstream</title>
    <updated>2026-10-03T03:14:29.677965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for xstream</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0817-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:1420</id>
    <title>RHSA-2022:1420 — Red Hat Security Advisory: OpenShift Container Platform 3.11.685 security and bug fix update</title>
    <updated>2026-10-03T03:14:29.677982+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xstream: Injecting highly recursive collections or maps can cause a DoS workflow-cps: OS command execution through crafted SCM contents workflow-cps-global-lib: OS command execution through crafted SCM contents workflow-multibranch: OS command execution through crafted SCM contents workflow-cps: Pipeline-related plugins follow symbolic links or do not limit path names workflow-cps-global-lib: Pipeline-related plugins follow symbolic links or do not limit path names workflow-cps-global-lib: Pipeline-related plugins follow symbolic links or do not limit path names workflow-multibranch: Pipeline-related plugins follow symbolic links or do not limit path names workflow-cps: Password parameters are included from the original build in replayed builds workflow-cps-global-lib: Sandbox bypass vulnerability workflow-cps-global-lib: Sandbox bypass vulnerability workflow-cps-global-lib: Sandbox bypass vulnerability pipeline-build-step: Password parameter default values exposed</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:1420"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:0817-1</id>
    <title>SUSE-SU-2022:0817-1 — Security update for xstream</title>
    <updated>2026-10-03T03:14:29.678020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for xstream</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:0817-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43859</id>
    <title>UBUNTU-CVE-2021-43859</title>
    <updated>2026-10-03T03:14:29.678035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libxstream-java, Ubuntu:Pro:16.04:LTS: libxstream-java, Ubuntu:18.04:LTS: libxstream-java, Ubuntu:20.04:LTS: libxstream-java, Ubuntu:22.04:LTS: libxstream-java, Ubuntu:24.04:LTS: libxstream-java, Ubuntu:25.10: libxstream-java, Ubuntu:26.04:LTS: libxstream-java</p>
<p>XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</id>
    <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
    <updated>2026-10-03T03:14:29.678067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607"/>
  </entry>
</feed>
