<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:34:09.871524+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0090</id>
    <title>certfr-2024-avi-0090 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-03T09:34:09.878731+00:00</updated>
    <content>certfr-2024-avi-0090</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-227926</id>
    <title>EUVD-2026-227926</title>
    <updated>2026-10-03T09:34:09.878768+00:00</updated>
    <content>EUVD-2026-227926</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-227926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0105</id>
    <title>fkie_cve-2023-0105</title>
    <updated>2026-10-03T09:34:09.878783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-0105"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c7xw-p58w-h6fj</id>
    <title>GHSA-c7xw-p58w-h6fj — Keycloak: Impersonation and lockout possible through incorrect handling of email trust</title>
    <updated>2026-10-03T09:34:09.878810+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-core</p>
<p>Impersonation and lockout are possible due to email trust not being handled correctly in Keycloak. Since the verified state is not reset when the email changes, it is possible for users to shadow others with the same email and lock out or impersonate them.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c7xw-p58w-h6fj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-0105</id>
    <title>gsd-2023-0105</title>
    <updated>2026-10-03T09:34:09.878832+00:00</updated>
    <content>gsd-2023-0105</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-0105"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7482</id>
    <title>RHSA-2023:7482 — Red Hat Security Advisory: Red Hat Single Sign-On 7.6.6 security update on RHEL 7</title>
    <updated>2026-10-03T09:34:09.878843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak: impersonation and lockout possible through incorrect handling of email trust bouncycastle: potential  blind LDAP injection attack using a self-signed certificate HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7482"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0036</id>
    <title>WID-SEC-W-2023-0036 — Keycloak: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T09:34:09.878862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Sicherheitsvorkehrungen zu umgehen und dadurch Nutzerrechte zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0036"/>
  </entry>
</feed>
