<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:49:01.235869+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-wa25182</id>
    <title>CLEANSTART-2026-WA25182 — Security fix for CVE-2025-1396 applied in: wso2is 7.2.0-r2</title>
    <updated>2026-10-03T01:49:01.298154+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: wso2is</p>
<p>Security vulnerability affects the wso2is package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-wa25182"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253833</id>
    <title>EUVD-2026-253833</title>
    <updated>2026-10-03T01:49:01.298219+00:00</updated>
    <content>EUVD-2026-253833</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253833"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-1396</id>
    <title>fkie_cve-2025-1396</title>
    <updated>2026-10-03T01:49:01.298237+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system returns a distinct "User does not exist" error message to the login form, regardless of the validate_username setting. This behavior allows malicious actors to determine which usernames exist in the system based on observable discrepancies in the application's responses.</p>
<p>Exploitation of this vulnerability could aid in brute-force attacks, targeted phishing campaigns, or other social engineering techniques by confirming the validity of user identifiers within the system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-1396"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w82p-r9vw-4rg5</id>
    <title>GHSA-w82p-r9vw-4rg5 — WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled</title>
    <updated>2026-10-03T01:49:01.298268+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.wso2.carbon.identity.framework:org.wso2.carbon.identity.input.validation.mgt</p>
<p>A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system returns a distinct "User does not exist" error message to the login form, regardless of the validate_username setting. This behavior allows malicious actors to determine which usernames exist in the system based on observable discrepancies in the application's responses.</p>
<p>Exploitation of this vulnerability could aid in brute-force attacks, targeted phishing campaigns, or other social engineering techniques by confirming the validity of user identifiers within the system.</p>
<p>There is a fix available in version 7.8.491, however it has not been published to the Maven registry.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w82p-r9vw-4rg5"/>
  </entry>
</feed>
