<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:35:03.200361+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0792</id>
    <title>certfr-2025-avi-0792 — De multiples vulnérabilités ont été découvertes dans les produits Spring. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T19:35:03.372573+00:00</updated>
    <content>certfr-2025-avi-0792</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0792"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ft93686</id>
    <title>CLEANSTART-2026-FT93686 — Security fix for CVE-2025-41249 applied in: activemq 5.19.8-r3, activemq 6.1.8-r1, apache-hive 4.0.0-r0, apache-hive 4.…</title>
    <updated>2026-10-02T19:35:03.372624+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: activemq, CleanStart: apache-hive</p>
<p>CVE-2025-41249 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ft93686"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-252828</id>
    <title>EUVD-2026-252828</title>
    <updated>2026-10-02T19:35:03.372662+00:00</updated>
    <content>EUVD-2026-252828</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-252828"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41249</id>
    <title>fkie_cve-2025-41249</title>
    <updated>2026-10-02T19:35:03.372676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.</p>
<p>Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.</p>
<p>You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.</p>
<p>This CVE is published in conjunction with  CVE-2025-41248 https://spring.io/security/cve-2025-41248 .</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-41249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jmp9-x22r-554x</id>
    <title>GHSA-jmp9-x22r-554x — Spring Framework annotation detection mechanism may result in improper authorization</title>
    <updated>2026-10-02T19:35:03.372705+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.springframework:spring-core</p>
<p>The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.</p>
<p>Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.</p>
<p>You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.</p>
<p>This CVE is published in conjunction with  CVE-2025-41248 https://spring.io/security/cve-2025-41248 .</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jmp9-x22r-554x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-010299</id>
    <title>jvndb-2026-010299</title>
    <updated>2026-10-02T19:35:03.372732+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities exist in Hitachi Ops Center Common Services.

CVE-2024-4028, CVE-2025-8714, CVE-2025-8715, CVE-2025-10044, CVE-2025-12817, CVE-2025-12818, CVE-2025-41248, CVE-2025-41249

(*)CVE-2026-1190 is removed from the list.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-010299"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0020</id>
    <title>NCSC-2026-0020 — Kwetsbaarheden verholpen in Oracle Commerce</title>
    <updated>2026-10-02T19:35:03.372750+00:00</updated>
    <content>NCSC-2026-0020</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0020"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:18028</id>
    <title>RHSA-2025:18028 — Red Hat Security Advisory: Red Hat Build of Apache Camel 4.10.7 for Spring Boot release.</title>
    <updated>2026-10-02T19:35:03.372775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.eclipse.jgit: XXE vulnerability in Eclipse JGit org.springframework.security/spring-security-core: Spring Security authorization bypass org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions io.minio/minio: minio-java Client XML Tag is Vulnerable to Value Substitution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:18028"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-41249</id>
    <title>UBUNTU-CVE-2025-41249</title>
    <updated>2026-10-02T19:35:03.372798+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java</p>
<p>The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with  CVE-2025-41248 https://spring.io/security/cve-2025-41248 .</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-41249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2060</id>
    <title>WID-SEC-W-2025-2060 — VMware Tanzu Spring Framework und Spring Security: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrung…</title>
    <updated>2026-10-02T19:35:03.372832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Security und VMware Tanzu Spring Framework ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2060"/>
  </entry>
</feed>
