<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:00:04.876451+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-344</id>
    <title>certfr-2022-avi-344 — Une vulnérabilité a été découverte dans VMware Spring. Elle permet à un
attaquant de provoquer un contournement de la p…</title>
    <updated>2026-10-03T00:00:04.989665+00:00</updated>
    <content>certfr-2022-avi-344</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-344"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-13656</id>
    <title>EUVD-2026-13656</title>
    <updated>2026-10-03T00:00:04.989711+00:00</updated>
    <content>EUVD-2026-13656</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-13656"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-22968</id>
    <title>fkie_cve-2022-22968</title>
    <updated>2026-10-03T00:00:04.989726+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-22968"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g5mm-vmx4-3rg7</id>
    <title>GHSA-g5mm-vmx4-3rg7 — Improper handling of case sensitivity in Spring Framework</title>
    <updated>2026-10-03T00:00:04.989756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.springframework:spring-context</p>
<p>In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. Versions 5.3.19 and 5.2.21 contain a patch for this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g5mm-vmx4-3rg7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-22968</id>
    <title>gsd-2022-22968</title>
    <updated>2026-10-03T00:00:04.989783+00:00</updated>
    <content>gsd-2022-22968</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-22968"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:5101</id>
    <title>RHSA-2022:5101 — Red Hat Security Advisory: Red Hat AMQ Broker 7.10.0 release and security update</title>
    <updated>2026-10-03T00:00:04.989795+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties jackson-databind: denial of service via a large depth of nested objects Broker: Malformed message can result in partial DoS (OOM) netty: control chars in header names may lead to HTTP request smuggling amq: AMQ Broker Operator ClusterWide Edit Permissions Due Token Exposure Framework: Data Binding Rules Vulnerability artemis-commons: Apache ActiveMQ Artemis DoS</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:5101"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22968</id>
    <title>UBUNTU-CVE-2022-22968</title>
    <updated>2026-10-03T00:00:04.989836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java</p>
<p>In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22968"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0068</id>
    <title>WID-SEC-W-2022-0068 — VMware Tanzu Spring Framework: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T00:00:04.989889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Framework ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0068"/>
  </entry>
</feed>
