<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:26:28.437061+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-05694</id>
    <title>bdu:2024-05694</title>
    <updated>2026-10-03T13:26:28.582468+00:00</updated>
    <content>bdu:2024-05694</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-05694"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366678</id>
    <title>EUVD-2026-366678</title>
    <updated>2026-10-03T13:26:28.582511+00:00</updated>
    <content>EUVD-2026-366678</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-6717</id>
    <title>fkie_cve-2023-6717</title>
    <updated>2026-10-03T13:26:28.582525+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-6717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8rmm-gm28-pj8q</id>
    <title>GHSA-8rmm-gm28-pj8q — Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flow</title>
    <updated>2026-10-03T13:26:28.582556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-services</p>
<p>Keycloak allows arbitrary URLs as SAML Assertion Consumer Service POST Binding URL (ACS), including JavaScript URIs (javascript:).</p>
<p>Allowing JavaScript URIs in combination with HTML forms leads to JavaScript evaluation in the context of the embedding origin on form submission.</p>
<p>#### Acknowledgements:
Special thanks to Lauritz Holtmann for reporting this issue and helping us improve our project.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8rmm-gm28-pj8q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-6717</id>
    <title>gsd-2023-6717</title>
    <updated>2026-10-03T13:26:28.582584+00:00</updated>
    <content>gsd-2023-6717</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-6717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1353</id>
    <title>RHSA-2024:1353 — Red Hat Security Advisory: Red Hat Process Automation Manager 7.13.5 security update</title>
    <updated>2026-10-03T13:26:28.582595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SnakeYaml: Constructor Deserialization Remote Code Execution xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Denial of Service by injecting recursive collections or maps based on element's hash values raising a stack overflow batik: Server-Side Request Forgery vulnerability batik: Server-Side Request Forgery vulnerability RESTEasy: creation of insecure temp files okio: GzipSource class improper exception handling JSON-java: parser confusion leads to OOM logback: A serialization vulnerability in logback receiver keycloak: XSS via assertion consumer service URL in SAML POST-binding flow bouncycastle: potential  blind LDAP injection attack using a self-signed certificate</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0914</id>
    <title>WID-SEC-W-2024-0914 — Red Hat Enterprise Linux (keycloak): Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:26:28.582637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Cross-Site Scripting (XSS)-Angriffe durchzuführen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0914"/>
  </entry>
</feed>
