<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:37:15.994317+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-00177</id>
    <title>bdu:2025-00177</title>
    <updated>2026-10-03T10:37:16.236767+00:00</updated>
    <content>bdu:2025-00177</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-00177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0337</id>
    <title>certfr-2025-avi-0337 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T10:37:16.236813+00:00</updated>
    <content>certfr-2025-avi-0337</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</id>
    <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
    <updated>2026-10-03T10:37:16.236833+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cassandra-fips</p>
<p>Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-208886</id>
    <title>EUVD-2026-208886</title>
    <updated>2026-10-03T10:37:16.236867+00:00</updated>
    <content>EUVD-2026-208886</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-208886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-12798</id>
    <title>fkie_cve-2024-12798</title>
    <updated>2026-10-03T10:37:16.236879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core
      upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows
      attacker to execute arbitrary code by compromising an existing
      logback configuration file or by injecting an environment variable
      before program execution.</p>
<p>Malicious logback configuration files can allow the attacker to execute 
arbitrary code using the JaninoEventEvaluator extension.</p>
<p>A successful attack requires the user to have write access to a 
configuration file. Alternatively, the attacker could inject a malicious 
environment variable pointing to a malicious configuration file. In both 
cases, the attack requires existing privilege.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-12798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pr98-23f8-jwxv</id>
    <title>GHSA-pr98-23f8-jwxv — QOS.CH logback-core Expression Language Injection vulnerability</title>
    <updated>2026-10-03T10:37:16.236908+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: ch.qos.logback:logback-core</p>
<p>ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core up to and including version 1.5.12 in Java applications allows attackers to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution.</p>
<p>Malicious logback configuration files can allow the attacker to execute arbitrary code using the JaninoEventEvaluator extension.</p>
<p>A successful attack requires the user to have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privilege.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pr98-23f8-jwxv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-010300</id>
    <title>jvndb-2026-010300</title>
    <updated>2026-10-03T10:37:16.236933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Hitachi Ops Center Viewpoint contain the following vulnerabilities:

CVE-2014-3643, CVE-2023-3635, CVE-2023-6378, CVE-2023-6481, CVE-2023-35116, CVE-2024-12798, CVE-2024-12801, CVE-2024-47554</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-010300"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1082</id>
    <title>OESA-2025-1082 — logback security update</title>
    <updated>2026-10-03T10:37:16.236951+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: logback, openEuler:22.03-LTS-SP3: logback, openEuler:22.03-LTS-SP4: logback, openEuler:24.03-LTS: logback, openEuler:24.03-LTS-SP1: logback</p>
<p>Logback is intended as a successor to the popular log4j project.

Security Fix(es):</p>
<p>ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core
      upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows
      attacker to execute arbitrary code by compromising an existing
      logback configuration file or by injecting an environment variable
      before program execution.</p>
<p>Malicious logback configuration files can allow the attacker to execute 
arbitrary code using the JaninoEventEvaluator extension.</p>
<p>A successful attack requires the user to have write access to a 
configuration file. Alternatively, the attacker could inject a malicious 
environment variable pointing to a malicious configuration file. In both 
cases, the attack requires existing privilege.(CVE-2024-12798)</p>
<p>Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to 
forge requests by compromising logback configuration files in XML.</p>
<p>The attacks involves the modification of DOCTYPE declaration in  XML configuration files.(CVE-2024-12801)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1082"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14627-1</id>
    <title>openSUSE-SU-2025:14627-1 — logback-1.2.11-4.1 on GA media</title>
    <updated>2026-10-03T10:37:16.236989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>logback-1.2.11-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14627-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:1078</id>
    <title>RHSA-2025:1078 — Red Hat Security Advisory: Red Hat Build of Apache Camel 4.8.3 for Spring Boot security update.</title>
    <updated>2026-10-03T10:37:16.237007+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>logback-core: arbitrary code execution via JaninoEventEvaluator mina-core: Apache MINA: applications using unbounded deserialization may allow RCE async-http-client: AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:1078"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0072-1</id>
    <title>SUSE-SU-2025:0072-1 — Security update for logback</title>
    <updated>2026-10-03T10:37:16.237028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for logback</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0072-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12798</id>
    <title>UBUNTU-CVE-2024-12798</title>
    <updated>2026-10-03T10:37:16.237042+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:22.04:LTS: logback, Ubuntu:24.04:LTS: logback</p>
<p>ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core       upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows       attacker to execute arbitrary code by compromising an existing       logback configuration file or by injecting an environment variable       before program execution. Malicious logback configuration files can allow the attacker to execute arbitrary code using the JaninoEventEvaluator extension. A successful attack requires the user to have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privilege.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0284</id>
    <title>WID-SEC-W-2025-0284 — Apache Camel for Spring Boot: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:37:16.237071+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Apache Camel, Red Hat Enterprise Linux und Red Hat Integration ausnutzen, um beliebigen Code auszuführen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0284"/>
  </entry>
</feed>
