<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:50:45.354317+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-03108</id>
    <title>bdu:2024-03108</title>
    <updated>2026-10-02T23:50:45.530033+00:00</updated>
    <content>bdu:2024-03108</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-03108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0298</id>
    <title>certfr-2024-avi-0298 — Une vulnérabilité a été découverte dans&lt;span class="textit"&gt; Spring
Framework&lt;/span&gt;. Elle permet à un attaquant de pro…</title>
    <updated>2026-10-02T23:50:45.530071+00:00</updated>
    <content>certfr-2024-avi-0298</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-217192</id>
    <title>EUVD-2026-217192</title>
    <updated>2026-10-02T23:50:45.530090+00:00</updated>
    <content>EUVD-2026-217192</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-217192"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-22262</id>
    <title>fkie_cve-2024-22262</title>
    <updated>2026-10-02T23:50:45.530103+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.</p>
<p>This is the same as  CVE-2024-22259 https://spring.io/security/cve-2024-22259  and  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-22262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2wrp-6fg6-hmc5</id>
    <title>GHSA-2wrp-6fg6-hmc5 — Spring Framework URL Parsing with Host Validation</title>
    <updated>2026-10-02T23:50:45.530134+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.springframework:spring-web</p>
<p>Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.</p>
<p>This is the same as  CVE-2024-22259 https://spring.io/security/cve-2024-22259  and  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2wrp-6fg6-hmc5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-22262</id>
    <title>gsd-2024-22262</title>
    <updated>2026-10-02T23:50:45.530162+00:00</updated>
    <content>gsd-2024-22262</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-22262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-261-04</id>
    <title>ICSA-25-261-04 — Multiple Open-Source Software Vulnerabilities in Hitachi Energy Asset Suite Product</title>
    <updated>2026-10-02T23:50:45.530173+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Hitachi Energy is aware of multiple reported vulnerabilities that affect the Asset Suite product versions mentioned in this document below. If exploited these vulnerabilities can potentially impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-261-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:3708</id>
    <title>RHSA-2024:3708 — Red Hat Security Advisory: Red Hat Build of Apache Camel 3.20.6 for Spring Boot security update.</title>
    <updated>2026-10-02T23:50:45.530194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data santuario: Private Key disclosure in debug-log output spring-security: Broken Access Control With Direct Use of AuthenticatedVoter springframework: URL Parsing with Host Validation cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:3708"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-22262</id>
    <title>UBUNTU-CVE-2024-22262</title>
    <updated>2026-10-02T23:50:45.530217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java</p>
<p>Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as  CVE-2024-22259 https://spring.io/security/cve-2024-22259  and  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-22262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0854</id>
    <title>WID-SEC-W-2024-0854 — VMware Tanzu Spring Framework: Schwachstelle ermöglicht Manipulation von Daten</title>
    <updated>2026-10-02T23:50:45.530249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Framework ausnutzen, um Daten zu manipulieren oder Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0854"/>
  </entry>
</feed>
