<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:39:14.475083+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-227951</id>
    <title>EUVD-2026-227951</title>
    <updated>2026-10-03T01:39:14.550969+00:00</updated>
    <content>EUVD-2026-227951</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-227951"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0091</id>
    <title>fkie_cve-2023-0091</title>
    <updated>2026-10-03T01:39:14.551006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-0091"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v436-q368-hvgg</id>
    <title>GHSA-v436-q368-hvgg — Keycloak has lack of validation of access token on client registrations endpoint</title>
    <updated>2026-10-03T01:39:14.551039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-core</p>
<p>When a service account with the create-client or manage-clients role can use the client-registration endpoints to create/manage clients with an access token.</p>
<p>If the access token is leaked, there is an option to revoke the specific token. However, the check is not performed in client-registration endpoints.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v436-q368-hvgg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-0091</id>
    <title>gsd-2023-0091</title>
    <updated>2026-10-03T01:39:14.551065+00:00</updated>
    <content>gsd-2023-0091</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-0091"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:1043</id>
    <title>RHSA-2023:1043 — Red Hat Security Advisory: Red Hat Single Sign-On 7.6.2 security update on RHEL 7</title>
    <updated>2026-10-03T01:39:14.551077+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &lt;option&gt; tag in HTML passed to DOM manipulation methods glob-parent: Regular Expression Denial of Service minimist: prototype pollution keycloak: HTML injection in execute-actions-email Admin REST API keycloak: XSS on impersonation under specific circumstances SnakeYaml: Constructor Deserialization Remote Code Execution Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations keycloak: Session takeover with OIDC offline refreshtokens keycloak: reflected XSS attack Moment.js: Path traversal  in moment.locale snakeyaml: Denial of Service due to missing nested depth limitation for collections moment: inefficient parsing algorithm resulting in DoS loader-utils: Regular expression denial of service snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or J…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:1043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0034</id>
    <title>WID-SEC-W-2023-0034 — Keycloak: Schwachstelle ermöglicht Manipulation von Daten</title>
    <updated>2026-10-03T01:39:14.551138+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0034"/>
  </entry>
</feed>
