<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:05:28.924075+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10867</id>
    <title>bdu:2026-10867</title>
    <updated>2026-10-03T10:05:29.778684+00:00</updated>
    <content>bdu:2026-10867</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10867"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</id>
    <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T10:05:29.778825+00:00</updated>
    <content>certfr-2026-avi-0667</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-qq48355</id>
    <title>Withdrawn: CLEANSTART-2026-QQ48355 — Security fixes in kserve-modelmesh 0.12.0-r17</title>
    <updated>2026-10-03T10:05:29.778855+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: kserve-modelmesh</p>
<p>Package kserve-modelmesh version 0.12.0-r17 fixes 53 vulnerabilities: ghsa-f6hv-jmp6-3vwv, ghsa-57rv-r2g8-2cj3, ghsa-xxqh-mfjm-7mv9, ghsa-m4cv-j2px-7723, ghsa-v8h7-rr48-vmmv...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-qq48355"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371779</id>
    <title>EUVD-2026-371779</title>
    <updated>2026-10-03T10:05:29.778924+00:00</updated>
    <content>EUVD-2026-371779</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14813</id>
    <title>fkie_cve-2025-14813</title>
    <updated>2026-10-03T10:05:29.778938+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).</p>
<p>This vulnerability is associated with program files G3413CTRBlockCipher.</p>
<p>This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-14813"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-574f-3g2m-x479</id>
    <title>GHSA-574f-3g2m-x479 — Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks</title>
    <updated>2026-10-03T10:05:29.778978+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.bouncycastle:bcprov-jdk14, Maven: org.bouncycastle:bcprov-jdk15to18, Maven: org.bouncycastle:bcprov-jdk18on, Maven: org.bouncycastle:bcprov-debug-jdk14, Maven: org.bouncycastle:bcprov-debug-jdk15to18, Maven: org.bouncycastle:bcprov-debug-jdk18on, Maven: org.bouncycastle:bcprov-ext-jdk14, Maven: org.bouncycastle:bcprov-ext-jdk15to18, Maven: org.bouncycastle:bcprov-ext-jdk18on, Maven: org.bouncycastle:bcprov-ext-debug-jdk14 and 4 more</p>
<p>The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-574f-3g2m-x479"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-03T10:05:29.779032+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10571-1</id>
    <title>openSUSE-SU-2026:10571-1 — bouncycastle-1.84-1.1 on GA media</title>
    <updated>2026-10-03T10:05:29.779156+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bouncycastle-1.84-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10571-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:11720</id>
    <title>RHSA-2026:11720 — Red Hat Security Advisory: Red Hat build of Quarkus 3.20.6.SP1 security update</title>
    <updated>2026-10-03T10:05:29.779179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid io.quarkus:quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:11720"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21404-1</id>
    <title>SUSE-SU-2026:21404-1 — Security update for bouncycastle</title>
    <updated>2026-10-03T10:05:29.779240+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for bouncycastle</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21404-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14813</id>
    <title>UBUNTU-CVE-2025-14813</title>
    <updated>2026-10-03T10:05:29.779263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: bouncycastle, Ubuntu:Pro:18.04:LTS: bouncycastle, Ubuntu:Pro:20.04:LTS: bouncycastle, Ubuntu:Pro:22.04:LTS: bouncycastle, Ubuntu:Pro:24.04:LTS: bouncycastle, Ubuntu:25.10: bouncycastle, Ubuntu:26.04:LTS: bouncycastle</p>
<p>: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).  This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14813"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1129</id>
    <title>WID-SEC-W-2026-1129 — Bouncy Castle BC-JAVA: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:05:29.779297+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Bouncy Castle BC-JAVA ausnutzen, um kryptografische Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1129"/>
  </entry>
</feed>
