<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:20:53.519084+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-03434</id>
    <title>bdu:2022-03434</title>
    <updated>2026-10-03T13:20:53.545133+00:00</updated>
    <content>bdu:2022-03434</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-03434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-tomcat-2022-29885</id>
    <title>BIT-tomcat-2022-29885 — EncryptInterceptor does not provide complete protection on insecure networks</title>
    <updated>2026-10-03T13:20:53.545170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: tomcat</p>
<p>The documentation of Apache Tomcat 10.1.0 to 10.1.0, 10.0.0 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-tomcat-2022-29885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-443</id>
    <title>certfr-2022-avi-443 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un
attaquant de provoquer un déni de service à dis…</title>
    <updated>2026-10-03T13:20:53.545204+00:00</updated>
    <content>certfr-2022-avi-443</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-443"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-aj47488</id>
    <title>Withdrawn: CLEANSTART-2026-AJ47488 — When using the RemoteIpFilter with requests received from a    reverse proxy via HTTP that include the X-Forwarded-Prot…</title>
    <updated>2026-10-03T13:20:53.545220+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: tomcat10</p>
<p>Multiple security vulnerabilities affect the tomcat10 package. When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-aj47488"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-49970</id>
    <title>cnvd-2022-49970</title>
    <updated>2026-10-03T13:20:53.545241+00:00</updated>
    <content>cnvd-2022-49970</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-49970"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-16308</id>
    <title>EUVD-2026-16308</title>
    <updated>2026-10-03T13:20:53.545253+00:00</updated>
    <content>EUVD-2026-16308</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-16308"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-29885</id>
    <title>fkie_cve-2022-29885</title>
    <updated>2026-10-03T13:20:53.545262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-29885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r84p-88g2-2vx2</id>
    <title>GHSA-r84p-88g2-2vx2 — Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption</title>
    <updated>2026-10-03T13:20:53.545282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat</p>
<p>The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r84p-88g2-2vx2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-29885</id>
    <title>gsd-2022-29885</title>
    <updated>2026-10-03T13:20:53.545303+00:00</updated>
    <content>gsd-2022-29885</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-29885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-29885</id>
    <title>UBUNTU-CVE-2022-29885</title>
    <updated>2026-10-03T13:20:53.545313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9</p>
<p>The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-29885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0467</id>
    <title>WID-SEC-W-2022-0467 — Apache Tomcat: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T13:20:53.545337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0467"/>
  </entry>
</feed>
