<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:15:01.938502+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06805</id>
    <title>bdu:2025-06805</title>
    <updated>2026-10-03T16:15:02.118781+00:00</updated>
    <content>bdu:2025-06805</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06805"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0514</id>
    <title>certfr-2025-avi-0514 — Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elle permet à un attaquant de provoquer un contournement de la…</title>
    <updated>2026-10-03T16:15:02.118824+00:00</updated>
    <content>certfr-2025-avi-0514</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-vy88502</id>
    <title>Withdrawn: CLEANSTART-2026-VY88502 — Security fixes in kogito-apps 10.1.0-r0</title>
    <updated>2026-10-03T16:15:02.118843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: kogito-apps</p>
<p>Package kogito-apps version 10.1.0-r0 fixes 26 vulnerabilities: CVE-2025-55163, ghsa-prj3-ccx8-p6x4, CVE-2025-67735, ghsa-84h7-rjj3-6jx4, CVE-2025-58057...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-vy88502"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-243898</id>
    <title>EUVD-2026-243898</title>
    <updated>2026-10-03T16:15:02.118876+00:00</updated>
    <content>EUVD-2026-243898</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-243898"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49146</id>
    <title>fkie_cve-2025-49146</title>
    <updated>2026-10-03T16:15:02.118889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-49146"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hq9p-pm7w-8p54</id>
    <title>GHSA-hq9p-pm7w-8p54 — pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration</title>
    <updated>2026-10-03T16:15:02.118913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.postgresql:postgresql</p>
<p>### Impact
When the PostgreSQL JDBC driver is configured with channel binding set to `required` (default value is `prefer`), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI  authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements.</p>
<p>### Patches
TBD</p>
<p>### Workarounds</p>
<p>Configure `sslMode=verify-full` to prevent MITM attacks.</p>
<p>### References</p>
<p>* https://www.postgresql.org/docs/current/sasl-authentication.html#SASL-SCRAM-SHA-256
* https://datatracker.ietf.org/doc/html/rfc7677
* https://datatracker.ietf.org/doc/html/rfc5802</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hq9p-pm7w-8p54"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0034</id>
    <title>NCSC-2026-0034 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-03T16:15:02.118940+00:00</updated>
    <content>NCSC-2026-0034</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15264-1</id>
    <title>openSUSE-SU-2025:15264-1 — postgresql-jdbc-42.7.7-1.1 on GA media</title>
    <updated>2026-10-03T16:15:02.118992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql-jdbc-42.7.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15264-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:10323</id>
    <title>RHSA-2025:10323 — Red Hat Security Advisory: Red Hat build of Cryostat security update</title>
    <updated>2026-10-03T16:15:02.119008+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/http: Request smuggling due to acceptance of invalid chunked data in net/http pgjdbc: pgjdbc insecure authentication in channel binding</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:10323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49146</id>
    <title>UBUNTU-CVE-2025-49146</title>
    <updated>2026-10-03T16:15:02.119026+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: libpgjava, Ubuntu:16.04:LTS: libpgjava, Ubuntu:Pro:18.04:LTS: libpgjava, Ubuntu:Pro:20.04:LTS: libpgjava, Ubuntu:22.04:LTS: libpgjava, Ubuntu:24.04:LTS: libpgjava, Ubuntu:25.10: libpgjava, Ubuntu:26.04:LTS: libpgjava</p>
<p>pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49146"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1328</id>
    <title>WID-SEC-W-2025-1328 — PostgreSQL JDBC Treiber: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-03T16:15:02.119058+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle im PostgreSQL JDBC Treiber ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1328"/>
  </entry>
</feed>
