<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:22:37.787954+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218</id>
    <title>certfr-2026-avi-0218 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T07:22:37.937530+00:00</updated>
    <content>certfr-2026-avi-0218</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-al62330</id>
    <title>CLEANSTART-2026-AL62330 — Security fix for CVE-2025-11966 applied in: apicurio-registry 3.1.7-r6, incubator-kie-kogito-data-index-ephemeral 10.1.…</title>
    <updated>2026-10-03T07:22:37.937575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: apicurio-registry, CleanStart: incubator-kie-kogito-data-index-ephemeral, CleanStart: keycloak, CleanStart: kogito-apps</p>
<p>CVE-2025-11966 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-al62330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-256607</id>
    <title>EUVD-2026-256607</title>
    <updated>2026-10-03T07:22:37.937616+00:00</updated>
    <content>EUVD-2026-256607</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-256607"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-11966</id>
    <title>fkie_cve-2025-11966</title>
    <updated>2026-10-03T07:22:37.937631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or directories within a served path can craft filenames containing malicious script or HTML content, leading to stored cross-site scripting (XSS) that executes in the context of users viewing the affected directory listing.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-11966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-45p5-v273-3qqr</id>
    <title>GHSA-45p5-v273-3qqr — Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names</title>
    <updated>2026-10-03T07:22:37.937657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.vertx:vertx-web</p>
<p># Description</p>
<p>- In the `StaticHandlerImpl#sendDirectoryListing(...)` method under the `text/html` branch, file and directory names are directly embedded into the `href`, `title`, and link text without proper HTML escaping.
- As a result, in environments where an attacker can control file names, injecting HTML/JavaScript is possible. Simply accessing the directory listing page will trigger an XSS.
- Affected Code:
    - File: `vertx-web/src/main/java/io/vertx/ext/web/handler/impl/StaticHandlerImpl.java`
    - Lines:
        - 709–713: `normalizedDir` is constructed without escaping
        - 714–731: `&lt;li&gt;&lt;a ...&gt;` elements insert file names directly into attributes and body without escaping
        - 744: parent directory name construction
        - 746–751: `{directory}`, `{parent}`, and `{files}` are inserted into the HTML template without escaping</p>
<p># Reproduction Steps</p>
<p>1. Prerequisites:
    - Directory listing is enabled using `StaticHandler`  
      (e.g., `StaticHandler.create("public").setDirectoryListing(true)`)
    - The attacker has the ability to create arbitrary file names under a public directory (e.g., via upload functionality or a shared directory)</p>
<p>2. Create a malicious file name (example for Unix-based OS):
    - Create an empty file in `public/` with one of the following names:
      - `&lt;img src=x onerror=alert('XSS')&gt;.txt`
      - Or attribute injection: `evil" onmouseover="alert('XSS')".txt`
    - Example:
      ```bash
      mkdir -p public
      printf…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-45p5-v273-3qqr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:23417</id>
    <title>RHSA-2025:23417 — Red Hat Security Advisory: Streams for Apache Kafka 3.1.0 release and security update</title>
    <updated>2026-10-03T07:22:37.937710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kafka: Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout io.vertx/vertx-core: Eclipse Vert.x Access Control Flaw io.vertx/vertx-web: Eclipse Vert.x cross site scripting org.apache.kafka: Kafka Client Arbitrary File Read SSRF apache-kafka: Apache Kafka: Possible RCE attack via SASL JAAS LdapLoginModule configuration org.apache.kafka: Kafka JNDI Login Module RCE Vulnerability commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang io.quarkus/quarkus-vertx: Quarkus potential data leak netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:23417"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0019</id>
    <title>WID-SEC-W-2026-0019 — Red Hat Enterprise Linux (Quarkus): Mehrere Schwachstellen</title>
    <updated>2026-10-03T07:22:37.937753+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0019"/>
  </entry>
</feed>
