<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:14:43.469587+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-02847</id>
    <title>bdu:2022-02847</title>
    <updated>2026-10-03T09:14:43.584875+00:00</updated>
    <content>bdu:2022-02847</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-02847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0512</id>
    <title>certfr-2025-avi-0512 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T09:14:43.584918+00:00</updated>
    <content>certfr-2025-avi-0512</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0512"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-38527</id>
    <title>cnvd-2022-38527</title>
    <updated>2026-10-03T09:14:43.584938+00:00</updated>
    <content>cnvd-2022-38527</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-38527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-15003</id>
    <title>EUVD-2026-15003</title>
    <updated>2026-10-03T09:14:43.584950+00:00</updated>
    <content>EUVD-2026-15003</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-15003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-26612</id>
    <title>fkie_cve-2022-26612</title>
    <updated>2026-10-03T09:14:43.584961+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry may extract an arbitrary file into the external directory using the symlink name. This however would be caught by the same targetDirPath check on Unix because of the getCanonicalPath call. However on Windows, getCanonicalPath doesn't resolve symbolic links, which bypasses the check. unpackEntries during TAR extraction follows symbolic links which allows writing outside expected base directory on Windows. This was addressed in Apache Hadoop 3.2.3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-26612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gx2c-fvhc-ph4j</id>
    <title>GHSA-gx2c-fvhc-ph4j — Path traversal in Hadoop</title>
    <updated>2026-10-03T09:14:43.584994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.hadoop:hadoop-common</p>
<p>In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry may extract an arbitrary file into the external directory using the symlink name. This however would be caught by the same targetDirPath check on Unix because of the getCanonicalPath call. However on Windows, getCanonicalPath doesn't resolve symbolic links, which bypasses the check. unpackEntries during TAR extraction follows symbolic links which allows writing outside expected base directory on Windows. This was addressed in Apache Hadoop 2.10.2, 3.2.3, 3.3.3, and 3.4.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gx2c-fvhc-ph4j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-26612</id>
    <title>gsd-2022-26612</title>
    <updated>2026-10-03T09:14:43.585022+00:00</updated>
    <content>gsd-2022-26612</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-26612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-2092</id>
    <title>OESA-2022-2092 — hadoop security update</title>
    <updated>2026-10-03T09:14:43.585041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: hadoop, openEuler:20.03-LTS-SP3: hadoop, openEuler:22.03-LTS: hadoop</p>
<p>Apache Hadoop is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models. It is designed to scale up from single servers to thousands of machines, each offering local computation and storage.

Security Fix(es):

In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry may extract an arbitrary file into the external directory using the symlink name. This however would be caught by the same targetDirPath check on Unix because of the getCanonicalPath call. However on Windows, getCanonicalPath doesn&amp;apos;t resolve symbolic links, which bypasses the check. unpackEntries during TAR extraction follows symbolic links which allows writing outside expected base directory on Windows. This was addressed in Apache Hadoop 3.2.3(CVE-2022-26612)

There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.(CVE-2021-37404)

Apache Hadoop&amp;apos;s FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-2092"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794</id>
    <title>WID-SEC-W-2024-0794 — Dell ECS: Mehrere Schwachstellen</title>
    <updated>2026-10-03T09:14:43.585117+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794"/>
  </entry>
</feed>
