<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:11:42.949342+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01705</id>
    <title>bdu:2026-01705</title>
    <updated>2026-10-02T16:11:43.237819+00:00</updated>
    <content>bdu:2026-01705</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</id>
    <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-02T16:11:43.237890+00:00</updated>
    <content>certfr-2025-avi-0622</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-254722</id>
    <title>EUVD-2026-254722</title>
    <updated>2026-10-02T16:11:43.237914+00:00</updated>
    <content>EUVD-2026-254722</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-254722"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4949</id>
    <title>fkie_cve-2025-4949</title>
    <updated>2026-10-02T16:11:43.237927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-4949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vrpq-qp53-qv56</id>
    <title>GHSA-vrpq-qp53-qv56 — Eclipse JGit XML External Entity (XXE) Vulnerability</title>
    <updated>2026-10-02T16:11:43.237960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.eclipse.jgit:org.eclipse.jgit</p>
<p>In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vrpq-qp53-qv56"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0027</id>
    <title>NCSC-2026-0027 — Kwetsbaarheden verholpen in Oracle Fusion Middleware</title>
    <updated>2026-10-02T16:11:43.237989+00:00</updated>
    <content>NCSC-2026-0027</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15232-1</id>
    <title>openSUSE-SU-2025:15232-1 — jgit-5.11.0-2.1 on GA media</title>
    <updated>2026-10-02T16:11:43.238042+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jgit-5.11.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15232-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:18028</id>
    <title>RHSA-2025:18028 — Red Hat Security Advisory: Red Hat Build of Apache Camel 4.10.7 for Spring Boot release.</title>
    <updated>2026-10-02T16:11:43.238060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.eclipse.jgit: XXE vulnerability in Eclipse JGit org.springframework.security/spring-security-core: Spring Security authorization bypass org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions io.minio/minio: minio-java Client XML Tag is Vulnerable to Value Substitution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:18028"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4949</id>
    <title>UBUNTU-CVE-2025-4949</title>
    <updated>2026-10-02T16:11:43.238084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: jgit, Ubuntu:18.04:LTS: jgit, Ubuntu:20.04:LTS: jgit, Ubuntu:22.04:LTS: jgit, Ubuntu:24.04:LTS: jgit, Ubuntu:25.10: jgit, Ubuntu:26.04:LTS: jgit</p>
<p>In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2160</id>
    <title>WID-SEC-W-2025-2160 — IBM App Connect Enterprise: Schwachstelle ermöglicht Offenlegung von Informationen, Denial of Service, und einen nicht…</title>
    <updated>2026-10-02T16:11:43.238138+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, und um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2160"/>
  </entry>
</feed>
