<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T23:53:54.611482+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03281</id>
    <title>bdu:2025-03281</title>
    <updated>2026-10-04T23:53:54.796548+00:00</updated>
    <content>bdu:2025-03281</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03281"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-23419</id>
    <title>BELL-CVE-2025-23419</title>
    <updated>2026-10-04T23:53:54.796583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: nginx, Alpaquita:stream: nginx</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-23419"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-nginx-2025-23419</id>
    <title>BIT-nginx-2025-23419 — TLS Session Resumption Vulnerability</title>
    <updated>2026-10-04T23:53:54.796613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: nginx</p>
<p>When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.</p>
<p>Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-nginx-2025-23419"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0099</id>
    <title>certfr-2025-avi-0099 — De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-04T23:53:54.796640+00:00</updated>
    <content>certfr-2025-avi-0099</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0099"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-af45008</id>
    <title>Withdrawn: CLEANSTART-2026-AF45008 — When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumptio…</title>
    <updated>2026-10-04T23:53:54.796655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: nginx</p>
<p>Multiple security vulnerabilities affect the nginx package. When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-af45008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266504</id>
    <title>EUVD-2026-266504</title>
    <updated>2026-10-04T23:53:54.796676+00:00</updated>
    <content>EUVD-2026-266504</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266504"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-23419</id>
    <title>fkie_cve-2025-23419</title>
    <updated>2026-10-04T23:53:54.796687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.</p>
<p>Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-23419"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-84xh-pwc6-7g4g</id>
    <title>GHSA-84xh-pwc6-7g4g</title>
    <updated>2026-10-04T23:53:54.796719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.</p>
<p>Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-84xh-pwc6-7g4g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-23419</id>
    <title>msrc_CVE-2025-23419 — TLS Session Resumption Vulnerability</title>
    <updated>2026-10-04T23:53:54.796737+00:00</updated>
    <content>msrc_CVE-2025-23419</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-23419"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1134</id>
    <title>OESA-2025-1134 — nginx security update</title>
    <updated>2026-10-04T23:53:54.796752+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: nginx, openEuler:24.03-LTS-SP1: nginx, openEuler:20.03-LTS-SP4: nginx, openEuler:22.03-LTS-SP3: nginx, openEuler:22.03-LTS-SP4: nginx</p>
<p>NGINX is a free, open-source, high-performance HTTP server and reverse proxy,  as well as an IMAP/POP3 proxy server.</p>
<p>Security Fix(es):</p>
<p>When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.</p>
<p>Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2025-23419)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1134"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14737-1</id>
    <title>openSUSE-SU-2025:14737-1 — nginx-1.27.4-1.1 on GA media</title>
    <updated>2026-10-04T23:53:54.796784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nginx-1.27.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14737-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23419</id>
    <title>UBUNTU-CVE-2025-23419</title>
    <updated>2026-10-04T23:53:54.796800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: nginx, Ubuntu:Pro:16.04:LTS: nginx, Ubuntu:Pro:18.04:LTS: nginx, Ubuntu:20.04:LTS: nginx, Ubuntu:22.04:LTS: nginx, Ubuntu:24.04:LTS: nginx</p>
<p>When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23419"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0274</id>
    <title>WID-SEC-W-2025-0274 — NGINX: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-04T23:53:54.796828+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in NGINX NGINX Plus und NGINX ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0274"/>
  </entry>
</feed>
