<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:12:01.984160+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-233335</id>
    <title>EUVD-2026-233335</title>
    <updated>2026-10-03T10:12:01.986933+00:00</updated>
    <content>EUVD-2026-233335</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-233335"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-46166</id>
    <title>fkie_cve-2022-46166</title>
    <updated>2026-10-03T10:12:01.986969+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-46166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w3x5-427h-wfq6</id>
    <title>GHSA-w3x5-427h-wfq6 — Spring Boot Admins integrated notifier support allows arbitrary code execution</title>
    <updated>2026-10-03T10:12:01.987029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: de.codecentric:spring-boot-admin</p>
<p>### Impact
All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are possibly affected.</p>
<p>### Patches
In the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 the issue is fixed by implementing `SimpleExecutionContext` of SpEL. This prevents the arbitrary code execution (i.e. SpEL injection).</p>
<p>### Workarounds
 * Disable any notifier
 * Disable write access (POST request) on `/env` actuator endpoint</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w3x5-427h-wfq6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-46166</id>
    <title>gsd-2022-46166</title>
    <updated>2026-10-03T10:12:01.987080+00:00</updated>
    <content>gsd-2022-46166</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-46166"/>
  </entry>
</feed>
