<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:46:24.664209+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ia43044</id>
    <title>Withdrawn: CLEANSTART-2026-IA43044 — Security fixes for CVE-2020-8908, CVE-2022-42889, CVE-2023-2976, CVE-2024-25710, CVE-2024-26308, CVE-2024-29371, CVE-20…</title>
    <updated>2026-10-04T03:46:24.951947+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: strimzi-kafka-operator</p>
<p>Multiple security vulnerabilities affect the strimzi-kafka-operator package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ia43044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255366</id>
    <title>EUVD-2026-255366</title>
    <updated>2026-10-04T03:46:24.952012+00:00</updated>
    <content>EUVD-2026-255366</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-31573</id>
    <title>fkie_cve-2024-31573</title>
    <updated>2026-10-04T03:46:24.952029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-31573"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-chfm-68vv-pvw5</id>
    <title>GHSA-chfm-68vv-pvw5 — XMLUnit for Java has Insecure Defaults when Processing XSLT Stylesheets</title>
    <updated>2026-10-04T03:46:24.952054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.xmlunit:xmlunit-core</p>
<p>### Impact
When performing XSLT transformations XMLUnit for Java did not disable XSLT extension functions by default. Depending on the XSLT processor being used this could allow arbitrary code to be executed when XMLUnit is used to transform data with a stylesheet who's source can not be trusted. If the stylesheet can be provided externally this may even lead to a remote code execution.</p>
<p>## Patches
Users are advised to upgrade to XMLUnit for Java 2.10.0 where the default has been changed by means of https://github.com/xmlunit/xmlunit/commit/b81d48b71dfd2868bdfc30a3e17ff973f32bc15b</p>
<p>### Workarounds
XMLUnit's main use-case is performing tests on code that generates or processes XML. Most users will not use it to perform arbitrary XSLT transformations.</p>
<p>Users running XSLT transformations with untrusted stylesheets should explicitly use XMLUnit's APIs to pass in a pre-configured TraX `TransformerFactory` with extension functions disabled via features and attributes. The required `setFactory` or `setTransformerFactory` methods have been available since XMLUnit for Java 2.0.0.</p>
<p>### References
[Bug Report](https://github.com/xmlunit/xmlunit/issues/264)
[JAXP Security Guide](https://docs.oracle.com/en/java/javase/22/security/java-api-xml-processing-jaxp-security-guide.html#GUID-E345AA09-801E-4B95-B83D-7F0C452538AA)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-chfm-68vv-pvw5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-31573</id>
    <title>gsd-2024-31573</title>
    <updated>2026-10-04T03:46:24.952091+00:00</updated>
    <content>gsd-2024-31573</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-31573"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-31573</id>
    <title>msrc_CVE-2024-31573 — XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (u…</title>
    <updated>2026-10-04T03:46:24.952104+00:00</updated>
    <content>msrc_CVE-2024-31573</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-31573"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1966</id>
    <title>OESA-2025-1966 — xmlunit security update</title>
    <updated>2026-10-04T03:46:24.952122+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: xmlunit</p>
<p>Security Fix(es):</p>
<p>A vulnerability was found in xmlunit-core. It has been declared as problematic.As an impact it is known to affect confidentiality, integrity, and availability.Upgrading to version 2.10.0 eliminates this vulnerability.(CVE-2024-31573)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-31573</id>
    <title>UBUNTU-CVE-2024-31573</title>
    <updated>2026-10-04T03:46:24.952143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: xmlunit, Ubuntu:18.04:LTS: xmlunit, Ubuntu:20.04:LTS: xmlunit, Ubuntu:22.04:LTS: xmlunit, Ubuntu:24.04:LTS: xmlunit, Ubuntu:25.10: xmlunit, Ubuntu:26.04:LTS: xmlunit</p>
<p>XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-31573"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1203</id>
    <title>WID-SEC-W-2026-1203 — Oracle Fusion Middleware: Mehrere Schwachstellen</title>
    <updated>2026-10-04T03:46:24.952169+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1203"/>
  </entry>
</feed>
