<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:04:28.634926+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02310</id>
    <title>bdu:2024-02310</title>
    <updated>2026-10-04T15:04:29.029438+00:00</updated>
    <content>bdu:2024-02310</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02310"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0180</id>
    <title>certfr-2024-avi-0180 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-04T15:04:29.029496+00:00</updated>
    <content>certfr-2024-avi-0180</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-mm56295</id>
    <title>Withdrawn: CLEANSTART-2026-MM56295 — Security fixes in spark-sc212-jdk17-py311 3.4.4-r0</title>
    <updated>2026-10-04T15:04:29.029517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: spark-sc212-jdk17-py311</p>
<p>Package spark-sc212-jdk17-py311 version 3.4.4-r0 fixes 45 vulnerabilities: ghsa-mjmj-j48q-9wg2, CVE-2022-1471, ghsa-r7pg-v2c8-mfg3, CVE-2024-47561, CVE-2023-39410...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-mm56295"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216707</id>
    <title>EUVD-2026-216707</title>
    <updated>2026-10-04T15:04:29.029549+00:00</updated>
    <content>EUVD-2026-216707</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216707"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-39410</id>
    <title>fkie_cve-2023-39410</title>
    <updated>2026-10-04T15:04:29.029562+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.</p>
<p>This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2.  Users should update to apache-avro version 1.11.3 which addresses this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-39410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rhrv-645h-fjfh</id>
    <title>GHSA-rhrv-645h-fjfh — Apache Avro Java SDK vulnerable to Improper Input Validation</title>
    <updated>2026-10-04T15:04:29.029586+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.avro:avro</p>
<p>When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.</p>
<p>This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2.  Users should update to apache-avro version 1.11.3 which addresses this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rhrv-645h-fjfh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-39410</id>
    <title>gsd-2023-39410</title>
    <updated>2026-10-04T15:04:29.029608+00:00</updated>
    <content>gsd-2023-39410</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-39410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1809</id>
    <title>OESA-2024-1809 — avro security update</title>
    <updated>2026-10-04T15:04:29.029619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: avro</p>
<p>Apache Avro is a data serialization system.

Security Fix(es):

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.

This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2.  Users should update to apache-avro version 1.11.3 which addresses this issue.

(CVE-2023-39410)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2023-188</id>
    <title>PYSEC-2023-188</title>
    <updated>2026-10-04T15:04:29.029640+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: avro</p>
<p>When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.</p>
<p>This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2.  Users should update to apache-avro version 1.11.3 which addresses this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2023-188"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7247</id>
    <title>RHSA-2023:7247 — Red Hat Security Advisory: Red Hat Fuse 7.12.1 release and security update</title>
    <updated>2026-10-04T15:04:29.029659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undertow: OutOfMemoryError due to @MultipartConfig handling okio: GzipSource class improper exception handling spring-security-webflux: path wildcard leads to security bypass jetty: hpack header values cause denial of service in http/2 jetty: Improper addition of quotation marks to user inputs in CgiServlet apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK jetty: Improper validation of HTTP/1 content-length jetty: OpenId Revoked authentication allows one request tomcat: FileUpload: DoS due to accumulation of temporary files on Windows tomcat: improper cleaning of recycled objects could lead to information leak HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) tomcat: incorrectly parsed http trailer headers can cause request smuggling activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3025</id>
    <title>WID-SEC-W-2023-3025 — IBM InfoSphere Information Server: Mehrere Schwachstellen</title>
    <updated>2026-10-04T15:04:29.029698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Cross-Site-Scripting-Angriffe durchzuführen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3025"/>
  </entry>
</feed>
