<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:31:38.381390+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05681</id>
    <title>bdu:2023-05681</title>
    <updated>2026-10-02T23:31:38.512019+00:00</updated>
    <content>bdu:2023-05681</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05681"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-jenkins-2022-2048</id>
    <title>BIT-jenkins-2022-2048</title>
    <updated>2026-10-02T23:31:38.512060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: jenkins</p>
<p>In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-jenkins-2022-2048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-952</id>
    <title>certfr-2022-avi-952 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
    <updated>2026-10-02T23:31:38.512095+00:00</updated>
    <content>certfr-2022-avi-952</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-952"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-12108</id>
    <title>EUVD-2026-12108</title>
    <updated>2026-10-02T23:31:38.512114+00:00</updated>
    <content>EUVD-2026-12108</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-12108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2048</id>
    <title>fkie_cve-2022-2048</title>
    <updated>2026-10-02T23:31:38.512125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-2048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wgmr-mf83-7x4j</id>
    <title>GHSA-wgmr-mf83-7x4j — Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service</title>
    <updated>2026-10-02T23:31:38.512148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.eclipse.jetty.http2:http2-server</p>
<p>### Description
Invalid HTTP/2 requests (for example, invalid URIs) are incorrectly handled by writing a blocking error response directly from the selector thread.
If the client manages to exhaust the HTTP/2 flow control window, or TCP congest the connection, the selector thread will be blocked trying to write the error response.
If this is repeated for all the selector threads, the server becomes unresponsive, causing the denial of service.</p>
<p>### Impact
A malicious client may render the server unresponsive.</p>
<p>### Patches
The fix is available in Jetty versions 9.4.47. 10.0.10, 11.0.10.</p>
<p>### Workarounds
No workaround available within Jetty itself.
One possible workaround is to filter the requests before sending them to Jetty (for example in a proxy)</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Email us at security@webtide.com.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wgmr-mf83-7x4j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-2048</id>
    <title>gsd-2022-2048</title>
    <updated>2026-10-02T23:31:38.512179+00:00</updated>
    <content>gsd-2022-2048</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-2048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1021</id>
    <title>OESA-2023-1021 — jetty security update</title>
    <updated>2026-10-02T23:31:38.512191+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: jetty</p>
<p>Jetty is a 100% Java HTTP Server and Servlet Container. This means that you do not need to configure and run a separate web server (like Apache) in order to use Java, servlets and JSPs to generate dynamic content. Jetty is a fully featured web server for static and dynamic content. Unlike separate server/container solutions, this means that your web server and web application run in the same process, without interconnection overheads and complications. Furthermore, as a pure java component, Jetty can be simply included in your application for demonstration, distribution or deployment. Jetty is available on all Java supported platforms.

Security Fix(es):

In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.(CVE-2022-2048)

In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.(CVE-2022-2047)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12182-1</id>
    <title>openSUSE-SU-2024:12182-1 — jetty-annotations-9.4.48-1.1 on GA media</title>
    <updated>2026-10-02T23:31:38.512219+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jetty-annotations-9.4.48-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12182-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:8652</id>
    <title>RHSA-2022:8652 — Red Hat Security Advisory: Red Hat Fuse 7.11.1 release and security update</title>
    <updated>2026-10-02T23:31:38.512237+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bootstrap: XSS in the tooltip or popover data-template attribute wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users json-smart: Denial of Service in JSONParserByteArray function minimist: prototype pollution urijs: Authorization Bypass Through User-Controlled Key http2-server: Invalid HTTP/2 requests cause DoS undertow: Large AJP request may cause DoS urijs: Leading white space bypasses protocol validation Moment.js: Path traversal  in moment.locale netty: world readable temporary file containing sensitive data snakeyaml: Denial of Service due to missing nested depth limitation for collections moment: inefficient parsing algorithm resulting in DoS postgresql: SQL Injection in ResultSet.refreshRow() with malicious column names apache-commons-configuration: Apache Commons Configuration insecure interpolation defaults snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode hsqldb: Untrusted input may lead to RCE attack apache-commons-text: variable interpolation RCE</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:8652"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2048</id>
    <title>UBUNTU-CVE-2022-2048</title>
    <updated>2026-10-02T23:31:38.512278+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: jetty, Ubuntu:14.04:LTS: jetty8, Ubuntu:16.04:LTS: jetty, Ubuntu:16.04:LTS: jetty8, Ubuntu:16.04:LTS: jetty9, Ubuntu:18.04:LTS: jetty9, Ubuntu:20.04:LTS: jetty9, Ubuntu:22.04:LTS: jetty9</p>
<p>In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0614</id>
    <title>WID-SEC-W-2022-0614 — Eclipse Jetty: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:31:38.512308+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um einen Denial of Service Angriff durchzuführen und Informationen zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0614"/>
  </entry>
</feed>
