<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:57:50.053710+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:6820</id>
    <title>ALSA-2022:6820 — Moderate: prometheus-jmx-exporter security update</title>
    <updated>2026-10-03T09:57:50.224036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: prometheus-jmx-exporter, AlmaLinux:8: prometheus-jmx-exporter-openjdk11</p>
<p>Prometheus JMX Exporter is a JMX to Prometheus exporter: a collector that can be configured to scrape and expose MBeans of a JMX target.</p>
<p>Security Fix(es):</p>
<p>* snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:6820"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05621</id>
    <title>bdu:2023-05621</title>
    <updated>2026-10-03T09:57:50.224128+00:00</updated>
    <content>bdu:2023-05621</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0034</id>
    <title>certfr-2023-avi-0034 — De multiples vulnérabilités ont été découvertes dans les produits
Oracle. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T09:57:50.224146+00:00</updated>
    <content>certfr-2023-avi-0034</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-173298</id>
    <title>EUVD-2026-173298</title>
    <updated>2026-10-03T09:57:50.224163+00:00</updated>
    <content>EUVD-2026-173298</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-173298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-25857</id>
    <title>fkie_cve-2022-25857</title>
    <updated>2026-10-03T09:57:50.224175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-25857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3mc7-4q67-w48m</id>
    <title>GHSA-3mc7-4q67-w48m — Uncontrolled Resource Consumption in snakeyaml</title>
    <updated>2026-10-03T09:57:50.224197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.yaml:snakeyaml</p>
<p>The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3mc7-4q67-w48m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-25857</id>
    <title>gsd-2022-25857</title>
    <updated>2026-10-03T09:57:50.224218+00:00</updated>
    <content>gsd-2022-25857</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-25857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-25857</id>
    <title>msrc_CVE-2022-25857 — Denial of Service (DoS)</title>
    <updated>2026-10-03T09:57:50.224229+00:00</updated>
    <content>msrc_CVE-2022-25857</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-25857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1162</id>
    <title>OESA-2023-1162 — snakeyaml security update</title>
    <updated>2026-10-03T09:57:50.224244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS: snakeyaml</p>
<p>SnakeYAML is a YAML parser and emitter for the Java Virtual Machine. YAML is a data serialization format designed for human readability and interaction with scripting languages.

Security Fix(es):

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.(CVE-2022-25857)

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38749)

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38750)

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38751)

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.(CVE-2022-38752)</p>
<p>Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12308-1</id>
    <title>openSUSE-SU-2024:12308-1 — snakeyaml-1.31-1.1 on GA media</title>
    <updated>2026-10-03T09:57:50.224287+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>snakeyaml-1.31-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12308-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6757</id>
    <title>RHSA-2022:6757 — Red Hat Security Advisory: Red Hat build of Eclipse Vert.x 4.3.3 security update</title>
    <updated>2026-10-03T09:57:50.224311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>snakeyaml: Denial of Service due to missing nested depth limitation for collections graphql-java: DoS by malicious query snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6757"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3560-1</id>
    <title>SUSE-SU-2022:3560-1 — Security update for snakeyaml</title>
    <updated>2026-10-03T09:57:50.224337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for snakeyaml</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3560-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25857</id>
    <title>UBUNTU-CVE-2022-25857</title>
    <updated>2026-10-03T09:57:50.224355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: snakeyaml, Ubuntu:Pro:16.04:LTS: snakeyaml, Ubuntu:18.04:LTS: snakeyaml, Ubuntu:20.04:LTS: snakeyaml, Ubuntu:22.04:LTS: snakeyaml</p>
<p>The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1635</id>
    <title>WID-SEC-W-2022-1635 — Red Hat OpenShift und Red Hat Enterprise Linux: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T09:57:50.224380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift build of Eclipse Vert.x und Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1635"/>
  </entry>
</feed>
