<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:29:08.789250+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-344259</id>
    <title>EUVD-2026-344259</title>
    <updated>2026-10-02T15:29:08.902399+00:00</updated>
    <content>EUVD-2026-344259</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-344259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-5379</id>
    <title>fkie_cve-2023-5379</title>
    <updated>2026-10-02T15:29:08.902441+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-5379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q462-4hrv-w27r</id>
    <title>GHSA-q462-4hrv-w27r</title>
    <updated>2026-10-02T15:29:08.902478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q462-4hrv-w27r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-5379</id>
    <title>gsd-2023-5379</title>
    <updated>2026-10-02T15:29:08.902498+00:00</updated>
    <content>gsd-2023-5379</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-5379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2353</id>
    <title>OESA-2024-2353 — undertow security update</title>
    <updated>2026-10-02T15:29:08.902510+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP3: undertow, openEuler:20.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP1: undertow, openEuler:24.03-LTS: undertow</p>
<p>Java web server using non-blocking IO

Security Fix(es):

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.(CVE-2021-3690)

A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).(CVE-2023-5379)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:9582</id>
    <title>RHSA-2025:9582 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.11 on RHEL 7 security update</title>
    <updated>2026-10-02T15:29:08.902546+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>wildfly: unsafe deserialization in Wildfly Enterprise Java Beans libthrift: potential DoS when processing untrusted payloads hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL undertow: special character in query results in server errors jackson-databind: denial of service via a large depth of nested objects jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629) wildfly-elytron: possible timing attacks via use of unsafe comparator undertow: Server identity in https connection is not checked by the undertow client undertow: AJP Request closes connection exceeding maxRequestSize EAP: wildfly-elytron has a SSRF security issue</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:9582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-5379</id>
    <title>UBUNTU-CVE-2023-5379</title>
    <updated>2026-10-02T15:29:08.902592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:Pro:20.04:LTS: undertow, Ubuntu:Pro:22.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow</p>
<p>A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-5379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1203</id>
    <title>WID-SEC-W-2025-1203 — NetApp ActiveIQ Unified Manager: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T15:29:08.902623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in NetApp ActiveIQ Unified Manager ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1203"/>
  </entry>
</feed>
