<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:54:20.387135+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264206</id>
    <title>EUVD-2026-264206</title>
    <updated>2026-10-03T04:54:20.498575+00:00</updated>
    <content>EUVD-2026-264206</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9162</id>
    <title>fkie_cve-2025-9162</title>
    <updated>2026-10-03T04:54:20.498611+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes placeholders within imported realm documents, potentially referencing environment variables. This substitution process
allows for injection attacks when crafted realm documents are processed. An attacker can leverage this to inject malicious content during the realm import procedure. This can lead to unintended consequences within the Keycloak environment.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-9162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8hxp-qmph-w5gq</id>
    <title>GHSA-8hxp-qmph-w5gq — Keycloak Potential Variable Reference in Model Storage Services</title>
    <updated>2026-10-03T04:54:20.498644+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-model-storage-services</p>
<p>A flaw was found in org.keycloak/keycloak-model-storage-service. The `KeycloakRealmImport` custom resource substitutes placeholders within imported realm documents, potentially referencing environment variables. This substitution process allows for injection attacks when crafted realm documents are processed. An attacker can leverage this to inject malicious content during the realm import procedure. This can lead to unintended consequences within the Keycloak environment.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8hxp-qmph-w5gq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:15336</id>
    <title>RHSA-2025:15336 — Red Hat Security Advisory: Red Hat build of Keycloak 26.0.15 Update</title>
    <updated>2026-10-03T04:54:20.498672+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.keycloak/keycloak-services: Keycloak SMTP Inject Vulnerability org.keycloak/keycloak-model-storage-service: Variable injection into environment variables</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:15336"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1892</id>
    <title>WID-SEC-W-2025-1892 — Keycloak: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-03T04:54:20.498693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1892"/>
  </entry>
</feed>
