<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:07:34.206346+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-03597</id>
    <title>bdu:2024-03597</title>
    <updated>2026-10-03T09:07:34.519443+00:00</updated>
    <content>bdu:2024-03597</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-03597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-tomcat-2022-45143</id>
    <title>BIT-tomcat-2022-45143 — Apache Tomcat: JsonErrorReportValve escaping</title>
    <updated>2026-10-03T09:07:34.519508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: tomcat</p>
<p>The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-tomcat-2022-45143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0001</id>
    <title>certfr-2023-avi-0001 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un
attaquant de provoquer un problème de sécurité…</title>
    <updated>2026-10-03T09:07:34.519571+00:00</updated>
    <content>certfr-2023-avi-0001</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-aj47488</id>
    <title>Withdrawn: CLEANSTART-2026-AJ47488 — When using the RemoteIpFilter with requests received from a    reverse proxy via HTTP that include the X-Forwarded-Prot…</title>
    <updated>2026-10-03T09:07:34.519604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: tomcat10</p>
<p>Multiple security vulnerabilities affect the tomcat10 package. When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-aj47488"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-19668</id>
    <title>EUVD-2026-19668</title>
    <updated>2026-10-03T09:07:34.519653+00:00</updated>
    <content>EUVD-2026-19668</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-19668"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-45143</id>
    <title>fkie_cve-2022-45143</title>
    <updated>2026-10-03T09:07:34.519678+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-45143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rq2w-37h9-vg94</id>
    <title>GHSA-rq2w-37h9-vg94 — Apache Tomcat improperly escapes input from JsonErrorReportValve</title>
    <updated>2026-10-03T09:07:34.519723+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat:tomcat-util</p>
<p>The `JsonErrorReportValve` in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 does not escape the `type`, `message` or `description` values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rq2w-37h9-vg94"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-45143</id>
    <title>gsd-2022-45143</title>
    <updated>2026-10-03T09:07:34.519782+00:00</updated>
    <content>gsd-2022-45143</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-45143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12847-1</id>
    <title>openSUSE-SU-2024:12847-1 — tomcat-9.0.43-16.1 on GA media</title>
    <updated>2026-10-03T09:07:34.519805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat-9.0.43-16.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12847-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:1663</id>
    <title>RHSA-2023:1663 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.2 release and security update</title>
    <updated>2026-10-03T09:07:34.519838+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: request smuggling tomcat: JsonErrorReportValve injection</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:1663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-45143</id>
    <title>UBUNTU-CVE-2022-45143</title>
    <updated>2026-10-03T09:07:34.519876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: tomcat9</p>
<p>The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-45143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0017</id>
    <title>WID-SEC-W-2023-0017 — Apache Tomcat: Schwachstelle ermöglicht Manipulation von Daten</title>
    <updated>2026-10-03T09:07:34.519919+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0017"/>
  </entry>
</feed>
