<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:34:54.934457+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05607</id>
    <title>bdu:2023-05607</title>
    <updated>2026-10-03T13:34:55.090704+00:00</updated>
    <content>bdu:2023-05607</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05607"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0513</id>
    <title>certfr-2023-avi-0513 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
    <updated>2026-10-03T13:34:55.090744+00:00</updated>
    <content>certfr-2023-avi-0513</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0513"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232059</id>
    <title>EUVD-2026-232059</title>
    <updated>2026-10-03T13:34:55.090764+00:00</updated>
    <content>EUVD-2026-232059</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232059"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-40151</id>
    <title>fkie_cve-2022-40151</title>
    <updated>2026-10-03T13:34:55.090776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-40151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f8cc-g7j8-xxpm</id>
    <title>GHSA-f8cc-g7j8-xxpm — XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow</title>
    <updated>2026-10-03T13:34:55.090804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.thoughtworks.xstream:xstream</p>
<p>### Impact
The vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream.</p>
<p>### Patches
XStream 1.4.20 handles the stack overflow and raises an InputManipulationException instead.</p>
<p>### Workarounds
The only solution is to catch the StackOverflowError in the client code calling XStream.</p>
<p>### References
See full information about the nature of the vulnerability and the steps to reproduce it in XStream's documentation for [CVE-2022-40151](https://x-stream.github.io/CVE-2022-40151.html).</p>
<p>### Credits
The vulnerability was discovered and reported by Henry Lin of the Google OSS-Fuzz team.</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in [XStream](https://github.com/x-stream/xstream/issues)
* Contact us at [XStream Google Group](https://groups.google.com/group/xstream-user)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f8cc-g7j8-xxpm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-40151</id>
    <title>gsd-2022-40151</title>
    <updated>2026-10-03T13:34:55.090837+00:00</updated>
    <content>gsd-2022-40151</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-40151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1929</id>
    <title>OESA-2023-1929 — xstream security update</title>
    <updated>2026-10-03T13:34:55.090848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: xstream, openEuler:20.03-LTS-SP3: xstream, openEuler:22.03-LTS: xstream, openEuler:22.03-LTS-SP1: xstream, openEuler:22.03-LTS-SP2: xstream</p>
<p>XStream is a simple library to serialize objects to XML and back again. A high level facade is supplied that simplifies common use cases. Custom objects can be serialized without need for specifying mappings. Speed and low memory footprint are a crucial part of the design, making it suitable for large object graphs or systems with high message throughput. No information is duplicated that can be obtained via reflection. This results in XML that is easier to read for humans and more compact than native Java serialization. XStream serializes internal fields, including private and final. Supports non-public and inner classes. Classes are not required to have default constructor. Duplicate references encountered in the object-model will be maintained. Supports circular references. By implementing an interface, XStream can serialize directly to/from any tree structure (not just XML). Strategies can be registered allowing customization of how particular types are represented as XML. When an exception occurs due to malformed XML, detailed diagnostics are provided to help isolate and fix the problem.

Security Fix(es):

Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.(CVE-2022-40151)

XStream serializes Java objects to XML and back again. Versions prior…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1929"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12796-1</id>
    <title>openSUSE-SU-2024:12796-1 — xstream-1.4.20-1.1 on GA media</title>
    <updated>2026-10-03T13:34:55.090890+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xstream-1.4.20-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12796-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:0469</id>
    <title>RHSA-2023:0469 — Red Hat Security Advisory: Red Hat Integration Camel Extensions For Quarkus 2.13.2</title>
    <updated>2026-10-03T13:34:55.090909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or JSON data xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS jackson-databind: use of deeply nested arrays apache-commons-text: variable interpolation RCE</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:0469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-40151</id>
    <title>UBUNTU-CVE-2022-40151</title>
    <updated>2026-10-03T13:34:55.090940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libxstream-java, Ubuntu:Pro:16.04:LTS: libxstream-java, Ubuntu:18.04:LTS: libxstream-java, Ubuntu:20.04:LTS: libxstream-java, Ubuntu:22.04:LTS: libxstream-java, Ubuntu:24.04:LTS: libxstream-java, Ubuntu:25.10: libxstream-java, Ubuntu:26.04:LTS: libxstream-java</p>
<p>Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-40151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0086</id>
    <title>WID-SEC-W-2023-0086 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:34:55.090968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um einen Denial of Service Angriff durchzuführen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0086"/>
  </entry>
</feed>
