<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:11:34.660938+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08956</id>
    <title>bdu:2025-08956</title>
    <updated>2026-10-03T07:11:35.321941+00:00</updated>
    <content>bdu:2025-08956</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08956"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</id>
    <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T07:11:35.321994+00:00</updated>
    <content>certfr-2025-avi-0622</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ax62295</id>
    <title>Withdrawn: CLEANSTART-2026-AX62295 — Security fixes in solr 9.8.0-r0</title>
    <updated>2026-10-03T07:11:35.322014+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: solr</p>
<p>Package solr version 9.8.0-r0 fixes 5 vulnerabilities: ghsa-72hv-8253-57qq, ghsa-j288-q9x7-2f5v, CVE-2025-48924, ghsa-7p63-w6x9-6gr7, CVE-2025-12383</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ax62295"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-260144</id>
    <title>EUVD-2026-260144</title>
    <updated>2026-10-03T07:11:35.322048+00:00</updated>
    <content>EUVD-2026-260144</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-260144"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48924</id>
    <title>fkie_cve-2025-48924</title>
    <updated>2026-10-03T07:11:35.322060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Uncontrolled Recursion vulnerability in Apache Commons Lang.</p>
<p>This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.</p>
<p>The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a 
StackOverflowError could cause an application to stop.</p>
<p>Users are recommended to upgrade to version 3.18.0, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-48924"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j288-q9x7-2f5v</id>
    <title>GHSA-j288-q9x7-2f5v — Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs</title>
    <updated>2026-10-03T07:11:35.322088+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.commons:commons-lang3, Maven: commons-lang:commons-lang</p>
<p>Uncontrolled Recursion vulnerability in Apache Commons Lang.</p>
<p>This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.</p>
<p>The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop.</p>
<p>Users are recommended to upgrade to version 3.18.0, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j288-q9x7-2f5v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-020740</id>
    <title>jvndb-2026-020740</title>
    <updated>2026-10-03T07:11:35.322116+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Hitachi Infrastructure Analytics Advisor contains the following vulnerability:

CVE-2025-48924

Hitachi Ops Center Analyzer contains the following vulnerabilities:

CVE-2025-48924

Hitachi Ops Center Analyzer viewpoint contains the following vulnerability:

CVE-2025-48924

Hitachi Ops Center Viewpoint contains the following vulnerabilities:

CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, CVE-2025-58056, CVE-2025-58057</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-020740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-48924</id>
    <title>msrc_CVE-2025-48924 — Apache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs</title>
    <updated>2026-10-03T07:11:35.322135+00:00</updated>
    <content>msrc_CVE-2025-48924</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-48924"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0020</id>
    <title>NCSC-2026-0020 — Kwetsbaarheden verholpen in Oracle Commerce</title>
    <updated>2026-10-03T07:11:35.322152+00:00</updated>
    <content>NCSC-2026-0020</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0020"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1929</id>
    <title>OESA-2025-1929 — apache-commons-lang3 security update</title>
    <updated>2026-10-03T07:11:35.322175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: apache-commons-lang3, openEuler:22.03-LTS-SP3: apache-commons-lang3, openEuler:22.03-LTS-SP4: apache-commons-lang3, openEuler:24.03-LTS: apache-commons-lang3, openEuler:24.03-LTS-SP1: apache-commons-lang3, openEuler:24.03-LTS-SP2: apache-commons-lang3</p>
<p>The standard Java libraries fail to provide enough methods for manipulation of its core classes. The Commons Lang Component provides these extra methods. Lang provides a host of helper utilities for the java.lang API, notably String manipulation methods, basic numerical methods, object reflection, concurrency, creation and serialization and System properties. Additionally it contains basic enhancements to java.util.Date and a series of utilities dedicated to help with building methods, such as hashCode, toString and equals. Note that Lang 3.0 (and subsequent versions) use a different package (org.apache.commons.lang3) than the previous versions (org.apache.commons.lang), allowing it to be used at the same time as an earlier version.

Security Fix(es):</p>
<p>A vulnerability classified as problematic has been found in Apache Commons Lang up to 2.6/3.17.x.CWE is classifying the issue as CWE-674. The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.This is going to have an impact on confidentiality, integrity, and availability.Upgrading to version 3.18.0 eliminates this vulnerability.(CVE-2025-48924)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1929"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15347-1</id>
    <title>openSUSE-SU-2025:15347-1 — apache-commons-lang3-3.18.0-1.1 on GA media</title>
    <updated>2026-10-03T07:11:35.322211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache-commons-lang3-3.18.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15347-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:12511</id>
    <title>RHSA-2025:12511 — Red Hat Security Advisory: Streams for Apache Kafka 3.0.0 release and security update</title>
    <updated>2026-10-03T07:11:35.322228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority jetty-server: Jetty: Gzip Request Body Buffer Corruption kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider netty: Denial of Service attack on windows app using Netty kafka: Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine netty: Denial of Service attack on windows app using Netty commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang io.quarkus/quarkus-vertx: Quarkus potential data leak com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:12511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02786-1</id>
    <title>SUSE-SU-2025:02786-1 — Security update for apache-commons-lang3</title>
    <updated>2026-10-03T07:11:35.322267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache-commons-lang3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02786-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48924</id>
    <title>UBUNTU-CVE-2025-48924</title>
    <updated>2026-10-03T07:11:35.322283+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libcommons-lang-java, Ubuntu:Pro:14.04:LTS: libcommons-lang3-java, Ubuntu:Pro:16.04:LTS: libcommons-lang-java, Ubuntu:Pro:16.04:LTS: libcommons-lang3-java, Ubuntu:Pro:18.04:LTS: libcommons-lang-java, Ubuntu:Pro:18.04:LTS: libcommons-lang3-java, Ubuntu:Pro:20.04:LTS: libcommons-lang-java, Ubuntu:Pro:20.04:LTS: libcommons-lang3-java, Ubuntu:22.04:LTS: libcommons-lang-java, Ubuntu:22.04:LTS: libcommons-lang3-java and 3 more</p>
<p>Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48924"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1540</id>
    <title>WID-SEC-W-2025-1540 — Apache Commons Lang: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T07:11:35.322329+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Commons Lang ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1540"/>
  </entry>
</feed>
