<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:58:01.752832+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-00169</id>
    <title>bdu:2023-00169</title>
    <updated>2026-10-02T23:58:01.861725+00:00</updated>
    <content>bdu:2023-00169</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-00169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241327</id>
    <title>EUVD-2026-241327</title>
    <updated>2026-10-02T23:58:01.861762+00:00</updated>
    <content>EUVD-2026-241327</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241327"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36944</id>
    <title>fkie_cve-2022-36944</title>
    <updated>2026-10-02T23:58:01.861776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-36944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8qv5-68g4-248j</id>
    <title>GHSA-8qv5-68g4-248j — Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserialization</title>
    <updated>2026-10-02T23:58:01.861807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.scala-lang:scala-library</p>
<p>Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with LazyList object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8qv5-68g4-248j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-36944</id>
    <title>gsd-2022-36944</title>
    <updated>2026-10-02T23:58:01.861832+00:00</updated>
    <content>gsd-2022-36944</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-36944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:3223</id>
    <title>RHSA-2023:3223 — Red Hat Security Advisory: Red Hat AMQ Streams 2.4.0 release and security update</title>
    <updated>2026-10-02T23:58:01.861844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-databind: denial of service via a large depth of nested objects okhttp: information disclosure via improperly used cryptographic function netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode netty: world readable temporary file containing sensitive data scala: deserialization gadget chain jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or JSON data jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS jackson-databind: use of deeply nested arrays Streams: component version with information disclosure flaw json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) kafka: RCE/DoS via SASL JAAS JndiLoginModule configuration in Kafka Connect</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:3223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36944</id>
    <title>Withdrawn: UBUNTU-CVE-2022-36944</title>
    <updated>2026-10-02T23:58:01.861882+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: scala, Ubuntu:Pro:18.04:LTS: scala, Ubuntu:Pro:20.04:LTS: scala, Ubuntu:22.04:LTS: scala, Ubuntu:24.04:LTS: scala, Ubuntu:25.04: scala</p>
<p>Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2345</id>
    <title>WID-SEC-W-2022-2345 — Camunda: Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-02T23:58:01.861911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Camunda ausnutzen, um seine Privilegien zu erhöhen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2345"/>
  </entry>
</feed>
