<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:37:14.547802+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-08465</id>
    <title>bdu:2023-08465</title>
    <updated>2026-10-03T02:37:15.668091+00:00</updated>
    <content>bdu:2023-08465</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-08465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276</id>
    <title>certfr-2023-avi-0276 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à un attaquant d…</title>
    <updated>2026-10-03T02:37:15.668163+00:00</updated>
    <content>certfr-2023-avi-0276</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-mg63413</id>
    <title>Withdrawn: CLEANSTART-2026-MG63413 — Security fixes in spark-sc213-jdk17-py312 3.5.8-r0</title>
    <updated>2026-10-03T02:37:15.668186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: spark-sc213-jdk17-py312</p>
<p>Package spark-sc213-jdk17-py312 version 3.5.8-r0 fixes 74 vulnerabilities: CVE-2026-54515, ghsa-5jmj-h7xm-6q6v, ghsa-337m-mw94-2v6g, CVE-2026-45205, ghsa-2r2c-cx56-8933...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-mg63413"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232058</id>
    <title>EUVD-2026-232058</title>
    <updated>2026-10-03T02:37:15.668226+00:00</updated>
    <content>EUVD-2026-232058</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-40152</id>
    <title>fkie_cve-2022-40152</title>
    <updated>2026-10-03T02:37:15.668240+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-40152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3f7h-mf4q-vrm4</id>
    <title>GHSA-3f7h-mf4q-vrm4 — Denial of Service due to parser crash</title>
    <updated>2026-10-03T02:37:15.668263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.fasterxml.woodstox:woodstox-core</p>
<p>Those using FasterXML/woodstox to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.</p>
<p>This vulnerability is only relevant for users making use of the DTD parsing functionality.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3f7h-mf4q-vrm4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-40152</id>
    <title>gsd-2022-40152</title>
    <updated>2026-10-03T02:37:15.668287+00:00</updated>
    <content>gsd-2022-40152</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-40152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2378</id>
    <title>OESA-2024-2378 — woodstox-core security update</title>
    <updated>2026-10-03T02:37:15.668299+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: woodstox-core, openEuler:24.03-LTS: woodstox-core, openEuler:22.03-LTS-SP4: woodstox-core, openEuler:22.03-LTS-SP3: woodstox-core, openEuler:20.03-LTS-SP4: woodstox-core</p>
<p>Woodstox is a high-performance validating namespace-aware StAX-compliant (JSR-173) Open Source XML-processor written in Java. XML processor means that it handles both input (== parsing) and output (== writing, serialization)), as well as supporting tasks such as validation.

Security Fix(es):

Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.(CVE-2022-40152)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2378"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13150-1</id>
    <title>openSUSE-SU-2024:13150-1 — jackson-dataformat-xml-2.15.2-1.1 on GA media</title>
    <updated>2026-10-03T02:37:15.668328+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-dataformat-xml-2.15.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13150-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:0469</id>
    <title>RHSA-2023:0469 — Red Hat Security Advisory: Red Hat Integration Camel Extensions For Quarkus 2.13.2</title>
    <updated>2026-10-03T02:37:15.668346+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or JSON data xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS jackson-databind: use of deeply nested arrays apache-commons-text: variable interpolation RCE</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:0469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:0592-1</id>
    <title>SUSE-SU-2023:0592-1 — Security update for SUSE Manager Server 4.2</title>
    <updated>2026-10-03T02:37:15.668377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for SUSE Manager Server 4.2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:0592-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-40152</id>
    <title>UBUNTU-CVE-2022-40152</title>
    <updated>2026-10-03T02:37:15.668395+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libxstream-java, Ubuntu:Pro:16.04:LTS: libxstream-java, Ubuntu:18.04:LTS: libxstream-java, Ubuntu:20.04:LTS: libxstream-java, Ubuntu:22.04:LTS: libxstream-java, Ubuntu:24.04:LTS: libxstream-java, Ubuntu:25.10: libxstream-java, Ubuntu:26.04:LTS: libxstream-java</p>
<p>Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-40152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0209</id>
    <title>WID-SEC-W-2023-0209 — Red Hat Integration Camel Extensions for Quarkus: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T02:37:15.668423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Integration Camel Extensions for Quarkus ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0209"/>
  </entry>
</feed>
