<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:53:40.011983+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05314</id>
    <title>bdu:2022-05314</title>
    <updated>2026-10-03T04:53:40.075952+00:00</updated>
    <content>bdu:2022-05314</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276</id>
    <title>certfr-2023-avi-0276 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à un attaquant d…</title>
    <updated>2026-10-03T04:53:40.076001+00:00</updated>
    <content>certfr-2023-avi-0276</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232647</id>
    <title>EUVD-2026-232647</title>
    <updated>2026-10-03T04:53:40.076034+00:00</updated>
    <content>EUVD-2026-232647</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232647"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36033</id>
    <title>fkie_cve-2022-36033</title>
    <updated>2026-10-03T04:53:40.076057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-36033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gp7f-rwcx-9369</id>
    <title>GHSA-gp7f-rwcx-9369 — jsoup may not sanitize code injection XSS attempts if SafeList.preserveRelativeLinks is enabled</title>
    <updated>2026-10-03T04:53:40.076114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jsoup:jsoup</p>
<p>jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow cross-site scripting (XSS) attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible.</p>
<p>### Impact
Sites that accept input HTML from users and use jsoup to sanitize that HTML, may be vulnerable to cross-site scripting (XSS) attacks, if they have enabled `SafeList.preserveRelativeLinks` and do not set an appropriate Content Security Policy.</p>
<p>### Patches
This issue is patched in jsoup 1.15.3.</p>
<p>Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version.</p>
<p>### Workarounds
To remediate this issue without immediately upgrading:</p>
<p>- disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs
- ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)</p>
<p>### Background and root cause
jsoup includes a [Cleaner](https://jsoup.org/apidocs/org/jsoup/safety/Cleaner.html) component, which is designed to [sanitize input HTML](https://jsoup.org/cookbook/…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gp7f-rwcx-9369"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-36033</id>
    <title>gsd-2022-36033</title>
    <updated>2026-10-03T04:53:40.076165+00:00</updated>
    <content>gsd-2022-36033</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-36033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-36033</id>
    <title>msrc_CVE-2022-36033 — jsoup may not sanitize Cross-Site Scripting (XSS) attempts if SafeList.preserveRelativeLinks is enabled</title>
    <updated>2026-10-03T04:53:40.076178+00:00</updated>
    <content>msrc_CVE-2022-36033</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-36033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1255</id>
    <title>OESA-2024-1255 — jsoup security update</title>
    <updated>2026-10-03T04:53:40.076194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: jsoup, openEuler:20.03-LTS-SP4: jsoup, openEuler:22.03-LTS: jsoup, openEuler:22.03-LTS-SP1: jsoup, openEuler:22.03-LTS-SP2: jsoup, openEuler:22.03-LTS-SP3: jsoup</p>
<p>jsoup is a Java library for working with real-world HTML. It provides a very convenient API for extracting and manipulating data, using the best of DOM, CSS, and jquery-like methods.

Security Fix(es):

jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)(CVE-2022-36033)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12413-1</id>
    <title>openSUSE-SU-2024:12413-1 — jsoup-1.15.3-1.1 on GA media</title>
    <updated>2026-10-03T04:53:40.076258+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jsoup-1.15.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12413-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:6656</id>
    <title>RHSA-2024:6656 — Red Hat Security Advisory: Migration Toolkit for Runtimes security, bug fix and enhancement update</title>
    <updated>2026-10-03T04:53:40.076297+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jsoup: The jsoup cleaner may incorrectly sanitize crafted XSS attempts if SafeList.preserveRelativeLinks is enabled</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:6656"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36033</id>
    <title>UBUNTU-CVE-2022-36033</title>
    <updated>2026-10-03T04:53:40.076317+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: jsoup, Ubuntu:16.04:LTS: jsoup, Ubuntu:18.04:LTS: jsoup, Ubuntu:20.04:LTS: jsoup, Ubuntu:22.04:LTS: jsoup, Ubuntu:24.04:LTS: jsoup, Ubuntu:25.10: jsoup, Ubuntu:26.04:LTS: jsoup</p>
<p>jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0133</id>
    <title>WID-SEC-W-2023-0133 — Oracle Financial Services Applications: Mehrere Schwachstellen</title>
    <updated>2026-10-03T04:53:40.076352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0133"/>
  </entry>
</feed>
