<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:54:49.110461+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01020</id>
    <title>bdu:2026-01020</title>
    <updated>2026-10-03T09:54:49.550981+00:00</updated>
    <content>bdu:2026-01020</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01020"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224</id>
    <title>certfr-2026-avi-0224 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T09:54:49.551049+00:00</updated>
    <content>certfr-2026-avi-0224</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-at07752</id>
    <title>CLEANSTART-2026-AT07752 — Security fix for CVE-2024-29371 applied in: apache-nifi 2.6.0-r3, apache-nifi 2.7.2-r7, confluent-common-docker 7.6.9-r…</title>
    <updated>2026-10-03T09:54:49.551087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: apache-nifi, CleanStart: confluent-common-docker, CleanStart: strimzi-kafka-operator</p>
<p>CVE-2024-29371 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-at07752"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266472</id>
    <title>EUVD-2026-266472</title>
    <updated>2026-10-03T09:54:49.551143+00:00</updated>
    <content>EUVD-2026-266472</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29371</id>
    <title>fkie_cve-2024-29371</title>
    <updated>2026-10-03T09:54:49.551166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-29371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3677-xxcr-wjqv</id>
    <title>GHSA-3677-xxcr-wjqv — jose4j is vulnerable to DoS via compressed JWE content</title>
    <updated>2026-10-03T09:54:49.551202+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.bitbucket.b_c:jose4j</p>
<p>In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3677-xxcr-wjqv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-29371</id>
    <title>gsd-2024-29371</title>
    <updated>2026-10-03T09:54:49.551254+00:00</updated>
    <content>gsd-2024-29371</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-29371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:5479</id>
    <title>RHSA-2024:5479 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.3 Security update</title>
    <updated>2026-10-03T09:54:49.551285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding netty-codec-http: Allocation of Resources Without Limits or Throttling jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack) org.bouncycastle:bcprov-jdk18on: Infinite loop in ED25519 verification in the ScalarUtil class</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:5479"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:1010-1</id>
    <title>SUSE-SU-2026:1010-1 — Security update 5.0.7 for Multi-Linux Manager Server</title>
    <updated>2026-10-03T09:54:49.551341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 5.0.7 for Multi-Linux Manager Server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:1010-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-29371</id>
    <title>UBUNTU-CVE-2024-29371</title>
    <updated>2026-10-03T09:54:49.551377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: libjose4j-java, Ubuntu:24.04:LTS: libjose4j-java, Ubuntu:25.10: libjose4j-java, Ubuntu:26.04:LTS: libjose4j-java</p>
<p>In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-29371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0517</id>
    <title>WID-SEC-W-2026-0517 — IBM WebSphere Application Server und WebSphere Application Server Liberty: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T09:54:49.551424+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM WebSphere Application Server und WebSphere Application Server Liberty ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0517"/>
  </entry>
</feed>
