<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:00:19.068987+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-639</id>
    <title>certfr-2022-avi-639 — Une vulnérabilité a été découverte dans Ruby on Rails. Elle permet à un
attaquant de provoquer une exécution de code ar…</title>
    <updated>2026-10-03T08:00:19.332159+00:00</updated>
    <content>certfr-2022-avi-639</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-639"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-309968</id>
    <title>EUVD-2026-309968</title>
    <updated>2026-10-03T08:00:19.332215+00:00</updated>
    <content>EUVD-2026-309968</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-309968"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-32224</id>
    <title>fkie_cve-2022-32224</title>
    <updated>2026-10-03T08:00:19.332231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record &lt; 7.0.3.1, &lt;6.1.6.1, &lt;6.0.5.1 and &lt;5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-32224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3hhc-qp5v-9p2j</id>
    <title>GHSA-3hhc-qp5v-9p2j — Active Record RCE bug with Serialized Columns</title>
    <updated>2026-10-03T08:00:19.332263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: activerecord</p>
<p>When serialized columns that use YAML (the default) are deserialized, Rails uses YAML.unsafe_load to convert the YAML data in to Ruby objects. If an attacker can manipulate data in the database (via means like SQL injection), then it may be possible for the attacker to escalate to an RCE.</p>
<p>There are no feasible workarounds for this issue, but other coders (such as JSON) are not impacted.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3hhc-qp5v-9p2j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-32224</id>
    <title>gsd-2022-32224</title>
    <updated>2026-10-03T08:00:19.332293+00:00</updated>
    <content>gsd-2022-32224</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-32224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2023:0009-1</id>
    <title>openSUSE-SU-2023:0009-1 — Security update for rubygem-activerecord-5.2</title>
    <updated>2026-10-03T08:00:19.332305+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-activerecord-5.2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2023:0009-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:0261</id>
    <title>RHSA-2023:0261 — Red Hat Security Advisory: Satellite 6.12.1 Async Security Update</title>
    <updated>2026-10-03T08:00:19.332323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>activerecord: Possible RCE escalation bug with Serialized Columns in Active Record jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS apache-commons-text: variable interpolation RCE</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:0261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-32224</id>
    <title>UBUNTU-CVE-2022-32224</title>
    <updated>2026-10-03T08:00:19.332343+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails</p>
<p>A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record &lt; 7.0.3.1, &lt;6.1.6.1, &lt;6.0.5.1 and &lt;5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-32224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0662</id>
    <title>WID-SEC-W-2022-0662 — Ruby on Rails: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-03T08:00:19.332375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann eine Schwachstelle in Ruby on Rails ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0662"/>
  </entry>
</feed>
