<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:29:02.125364+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14194</id>
    <title>bdu:2026-14194</title>
    <updated>2026-10-03T03:29:02.133083+00:00</updated>
    <content>bdu:2026-14194</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14194"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-hn92795</id>
    <title>CLEANSTART-2026-HN92795 — Security fix for CVE-2025-49574 applied in: incubator-kie-kogito-data-index-ephemeral 10.1.0-r1, kogito-apps 10.1.0-r0</title>
    <updated>2026-10-03T03:29:02.133115+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: incubator-kie-kogito-data-index-ephemeral, CleanStart: kogito-apps</p>
<p>CVE-2025-49574 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-hn92795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264249</id>
    <title>EUVD-2026-264249</title>
    <updated>2026-10-03T03:29:02.133147+00:00</updated>
    <content>EUVD-2026-264249</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49574</id>
    <title>fkie_cve-2025-49574</title>
    <updated>2026-10-03T03:29:02.133159+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1, 3.20.2, and 3.15.6, there is a potential data leak when duplicating a duplicated context. Quarkus extensively uses the Vert.x duplicated context to implement context propagation. With the new semantic data from one transaction can leak to the data from another transaction. From a Vert.x point of view, this new semantic clarifies the behavior. A significant amount of data is stored in the duplicated context, including request scope, security details, and metadata. Duplicating a duplicated context is rather rare and is only done in a few places. This issue has been patched in version 3.24.1, 3.20.2, and 3.15.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-49574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9623-mj7j-p9v4</id>
    <title>GHSA-9623-mj7j-p9v4 — Quarkus potentially leaks data when duplicating a duplicated context</title>
    <updated>2026-10-03T03:29:02.133182+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.quarkus:quarkus-vertx</p>
<p>### Impact</p>
<p>Vert.x 4.5.12 has changed the semantics of the duplication of duplicated context.</p>
<p>Duplicated context is an object used to propagate data through a processing (synchronous or asynchronous). Each "transaction" or "processing" runs on its own isolated duplicated context.</p>
<p>Initially, duplicating a duplicated context was creating a fresh (empty) new context, meaning that the new duplicated context can be used to managed a separated transaction.</p>
<p>In Vert.x 4.5.12, this semantics has changed, and since the content of the parent duplicated context is copied into the new one, potentially leaking data.</p>
<p>This CVE is especially for Quarkus as Quarkus extensively uses the Vert.x duplicated context to implement context propagation. With the new semantic data from one transaction can leak to the data from another transaction. From a Vert.x point of view, this new semantic clarifies the behavior.</p>
<p>A significant amount of data is stored in the duplicated context, including request scope, security details, and metadata. Duplicating a duplicated context is rather rare and is only done in a few places:</p>
<p>- Quarkus REST Client when using OTel (but it's the same transaction, so no leak)
- Quarkus Messaging connectors
- Quarkus SmallRye Health (same transaction, so no leak)</p>
<p>### Patches</p>
<p>After discussion with the Vert.x team, the change will be rolled back in Vert.x 4.x. A new API will be added to Vert.x 5 do distinguish the 2 cases.</p>
<p>### Workarounds</p>
<p>When duplicating a duplicated…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9623-mj7j-p9v4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:12511</id>
    <title>RHSA-2025:12511 — Red Hat Security Advisory: Streams for Apache Kafka 3.0.0 release and security update</title>
    <updated>2026-10-03T03:29:02.133226+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority jetty-server: Jetty: Gzip Request Body Buffer Corruption kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider netty: Denial of Service attack on windows app using Netty kafka: Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine netty: Denial of Service attack on windows app using Netty commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang io.quarkus/quarkus-vertx: Quarkus potential data leak com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:12511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1639</id>
    <title>WID-SEC-W-2025-1639 — Keycloak (Quarkus): Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-03T03:29:02.133258+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in Keycloak ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1639"/>
  </entry>
</feed>
