<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:13:03.508560+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0323</id>
    <title>certfr-2026-avi-0323 — De multiples vulnérabilités ont été découvertes dans les produits Spring. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T10:13:03.565917+00:00</updated>
    <content>certfr-2026-avi-0323</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276654</id>
    <title>EUVD-2026-276654</title>
    <updated>2026-10-03T10:13:03.565959+00:00</updated>
    <content>EUVD-2026-276654</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276654"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22733</id>
    <title>fkie_cve-2026-22733</title>
    <updated>2026-10-03T10:13:03.565982+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mgvc-8q2h-5pgc</id>
    <title>GHSA-mgvc-8q2h-5pgc — Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints</title>
    <updated>2026-10-03T10:13:03.566015+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.springframework.boot:spring-boot-starter-actuator</p>
<p>Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mgvc-8q2h-5pgc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0799</id>
    <title>WID-SEC-W-2026-0799 — VMware Tanzu Spring Boot Actuator: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T10:13:03.566043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Boot Actuator ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0799"/>
  </entry>
</feed>
