<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:49:45.011279+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04250</id>
    <title>bdu:2026-04250</title>
    <updated>2026-10-04T06:49:45.189711+00:00</updated>
    <content>bdu:2026-04250</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-jenkins-2026-33001</id>
    <title>BIT-jenkins-2026-33001</title>
    <updated>2026-10-04T06:49:45.189753+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: jenkins</p>
<p>Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-jenkins-2026-33001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-365481</id>
    <title>EUVD-2026-365481</title>
    <updated>2026-10-04T06:49:45.189787+00:00</updated>
    <content>EUVD-2026-365481</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-365481"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33001</id>
    <title>fkie_cve-2026-33001</title>
    <updated>2026-10-04T06:49:45.189801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r6qv-frpc-q66c</id>
    <title>GHSA-r6qv-frpc-q66c — Jenkins has a link following vulnerability allows arbitrary file creation</title>
    <updated>2026-10-04T06:49:45.189823+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.main:jenkins-core</p>
<p>Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r6qv-frpc-q66c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10199</id>
    <title>RHSA-2026:10199 — Red Hat Security Advisory: Release of Red Hat OpenShift Developer Tools - Openshift Jenkins 4.21 security update.</title>
    <updated>2026-10-04T06:49:45.189845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression org.jenkins-ci.main/jenkins-core: Jenkins: Stored Cross-site Scripting (XSS) via unescaped user-provided offline cause description org.jenkins-ci.main/jenkins-core: Jenkins: Information disclosure via unauthorized access to build parameters jenkins: Jenkins: Arbitrary file write and potential code execution through crafted archives</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0779</id>
    <title>WID-SEC-W-2026-0779 — Jenkins: Mehrere Schwachstellen</title>
    <updated>2026-10-04T06:49:45.189868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0779"/>
  </entry>
</feed>
