<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:18:38.810660+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0323</id>
    <title>certfr-2026-avi-0323 — De multiples vulnérabilités ont été découvertes dans les produits Spring. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T18:18:38.921253+00:00</updated>
    <content>certfr-2026-avi-0323</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bv41278</id>
    <title>Withdrawn: CLEANSTART-2026-BV41278 — Security fixes in kafka-ui 1.3.0-r2</title>
    <updated>2026-10-03T18:18:38.921335+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: kafka-ui</p>
<p>Package kafka-ui version 1.3.0-r2 fixes 13 vulnerabilities: ghsa-w9fj-cfpg-grvv, ghsa-4773-3jfm-qmx3, ghsa-pwqr-wmgm-9rr8, ghsa-mf92-479x-3373, ghsa-6hcq-hmm3-jj3c...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bv41278"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276652</id>
    <title>EUVD-2026-276652</title>
    <updated>2026-10-03T18:18:38.921368+00:00</updated>
    <content>EUVD-2026-276652</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276652"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22737</id>
    <title>fkie_cve-2026-22737</title>
    <updated>2026-10-03T18:18:38.921382+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4773-3jfm-qmx3</id>
    <title>GHSA-4773-3jfm-qmx3 — Spring Framework Improper Path Limitation with Script View Templates</title>
    <updated>2026-10-03T18:18:38.921406+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.springframework:spring-webmvc, Maven: org.springframework:spring-webflux</p>
<p>Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4773-3jfm-qmx3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22737</id>
    <title>UBUNTU-CVE-2026-22737</title>
    <updated>2026-10-03T18:18:38.921434+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java</p>
<p>Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0796</id>
    <title>WID-SEC-W-2026-0796 — VMware Tanzu Spring Framework (MVC and WebFlux): Mehrere Schwachstellen</title>
    <updated>2026-10-03T18:18:38.921464+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Framework ausnutzen, um Dateien zu manipulieren oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0796"/>
  </entry>
</feed>
