<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:01:08.777770+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-375992</id>
    <title>EUVD-2026-375992</title>
    <updated>2026-10-02T13:01:09.114026+00:00</updated>
    <content>EUVD-2026-375992</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-375992"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-15561</id>
    <title>fkie_cve-2026-15561</title>
    <updated>2026-10-02T13:01:09.114085+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-15561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fhmg-q5fc-2m8v</id>
    <title>GHSA-fhmg-q5fc-2m8v</title>
    <updated>2026-10-02T13:01:09.114118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fhmg-q5fc-2m8v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:53644</id>
    <title>RHSA-2026:53644 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.25 security pdate</title>
    <updated>2026-10-02T13:01:09.114137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid bouncycastle: BC-JAVA: private key leakage via non-constant time comparisons picketlink-federation: auth bypass in Picketlink SAML unsolicited-response undertow-core: Undertow: Authentication Bypass via AJP ssl_cert/is_ssl Forgery jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller picketlink-federation: picketlink SAML 2.0 auth bypass via missing assertions openjdk-orb: unauthed class loading via IIOP in EAP undertow-core: OOM via missing limits in chunked trailer in EAP's Undertow jboss-remoting: jboss-remoting: integer overflow in MessageReader leads to pre-authentication denial of service wildfly-iiop-openjdk: Missing authentication on EAP's IIOP NameService leads to MITM or DoS undertow: undertow-websockets: Undertow: Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method wildfly: wildfly-iiop: wildfly-jacorb: Wildfly: Pre-auth denial of service on the IIOP listener org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration du…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:53644"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15561</id>
    <title>UBUNTU-CVE-2026-15561</title>
    <updated>2026-10-02T13:01:09.114233+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:Pro:20.04:LTS: undertow, Ubuntu:Pro:22.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:26.04:LTS: undertow</p>
<p>A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15561"/>
  </entry>
</feed>
