<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T14:05:01.572833+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0867</id>
    <title>certfr-2025-avi-0867 — De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T14:05:01.993698+00:00</updated>
    <content>certfr-2025-avi-0867</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0867"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-272475</id>
    <title>EUVD-2026-272475</title>
    <updated>2026-10-04T14:05:01.993761+00:00</updated>
    <content>EUVD-2026-272475</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-272475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48913</id>
    <title>fkie_cve-2025-48913</title>
    <updated>2026-10-04T14:05:01.993777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities.  This interface is now restricted to reject those protocols, removing this possibility.</p>
<p>Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-48913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g4px-6qhm-hqjm</id>
    <title>GHSA-g4px-6qhm-hqjm — Apache CXF: Untrusted JMS configuration can lead to RCE</title>
    <updated>2026-10-04T14:05:01.993810+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.cxf:cxf-rt-transports-jms</p>
<p>If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities.  This interface is now restricted to reject those protocols, removing this possibility.</p>
<p>Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g4px-6qhm-hqjm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:17298</id>
    <title>RHSA-2025:17298 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.1.0 security update</title>
    <updated>2026-10-04T14:05:01.993838+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.apache.cxf/cxf: CXF JMS Code Execution Vulnerability netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:17298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1751</id>
    <title>WID-SEC-W-2025-1751 — Apache CXF: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-04T14:05:01.993861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Apache CXF ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1751"/>
  </entry>
</feed>
