<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:17:09.010641+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</id>
    <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T17:17:09.161346+00:00</updated>
    <content>certfr-2026-avi-1165</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</id>
    <title>Withdrawn: CLEANSTART-2026-AM39668 — yawkat LZ4 Java provides LZ4 compression for Java</title>
    <updated>2026-10-03T17:17:09.161399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-nifi</p>
<p>Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-323360</id>
    <title>EUVD-2026-323360</title>
    <updated>2026-10-03T17:17:09.161445+00:00</updated>
    <content>EUVD-2026-323360</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-323360"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10532</id>
    <title>fkie_cve-2026-10532</title>
    <updated>2026-10-03T17:17:09.161467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.</p>
<p>More precisely, an attacker able to influence serialized data sent to 
SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.</p>
<p>Although deserialization is heavily restricted by HardenedObjectInputStream and no 
practical way to achieve remote code execution or significant privilege 
escalation has been identified, this issue constitutes a bypass of the 
intended security restrictions.</p>
<p>This issue affects logback: through 1.5.33 inclusive.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-10532"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jhq6-gfmj-v8fx</id>
    <title>GHSA-jhq6-gfmj-v8fx — Logback vulnerable to Object Injection through HardenedObjectInputStream modules</title>
    <updated>2026-10-03T17:17:09.161516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: ch.qos.logback:logback-core</p>
<p>Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.</p>
<p>More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.</p>
<p>Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege  escalation has been identified, this issue constitutes a bypass of the  intended security restrictions.</p>
<p>This issue affects logback: through 1.5.33 inclusive.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jhq6-gfmj-v8fx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10999-1</id>
    <title>openSUSE-SU-2026:10999-1 — logback-1.5.34-1.1 on GA media</title>
    <updated>2026-10-03T17:17:09.161565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>logback-1.5.34-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10999-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10532</id>
    <title>UBUNTU-CVE-2026-10532</title>
    <updated>2026-10-03T17:17:09.161602+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:Pro:22.04:LTS: logback, Ubuntu:24.04:LTS: logback, Ubuntu:25.10: logback, Ubuntu:26.04:LTS: logback</p>
<p>Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects. Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions. This issue affects logback: through 1.5.33 inclusive.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10532"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2242</id>
    <title>WID-SEC-W-2026-2242 — IBM Operational Decision Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:17:09.161664+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Operational Decision Manager ausnutzen, um Sicherheitsbeschränkungen zu umgehen, um einen Denial of Service zu verursachen und Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2242"/>
  </entry>
</feed>
