<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:15:21.504780+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-11866</id>
    <title>bdu:2026-11866</title>
    <updated>2026-10-03T03:15:21.606858+00:00</updated>
    <content>bdu:2026-11866</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-11866"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-activemq-2026-33227</id>
    <title>BIT-activemq-2026-33227 — Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Lim…</title>
    <updated>2026-10-03T03:15:21.606895+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: activemq</p>
<p>Improper validation and restriction of a classpath path name vulnerability in</p>
<p>Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.</p>
<p>In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit.</p>
<p>This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Web: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ: before 5.19.3, from 6.0.0 before 6.2.2.</p>
<p>Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note: 5.19.3 and 6.2.2 also fix this issue, but that is limited to non-Windows environments due to a path separator resolution bug fixed in 5.19.4 and 6.2.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-activemq-2026-33227"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</id>
    <title>certfr-2026-avi-0901 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T03:15:21.606940+00:00</updated>
    <content>certfr-2026-avi-0901</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-281258</id>
    <title>EUVD-2026-281258</title>
    <updated>2026-10-03T03:15:21.606957+00:00</updated>
    <content>EUVD-2026-281258</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-281258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33227</id>
    <title>fkie_cve-2026-33227</title>
    <updated>2026-10-03T03:15:21.606968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper validation and restriction of a classpath path name vulnerability in</p>
<p>Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.</p>
<p>In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit.</p>
<p>This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Web: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ: before 5.19.3, from 6.0.0 before 6.2.2.</p>
<p>Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note: 5.19.3 and 6.2.2 also fix this issue, but that is limited to non-Windows environments due to a path separator resolution bug fixed in 5.19.4 and 6.2.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33227"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h2h4-5m64-m273</id>
    <title>GHSA-h2h4-5m64-m273 — Apache ActiveMQ: Improper validation and restriction of a classpath path name</title>
    <updated>2026-10-03T03:15:21.607000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.activemq:activemq-client, Maven: org.apache.activemq:activemq-broker, Maven: org.apache.activemq:activemq-all, Maven: org.apache.activemq:activemq-web</p>
<p>Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.</p>
<p>In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit. This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Web: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ: before 5.19.3, from 6.0.0 before 6.2.2.</p>
<p>Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note: 5.19.3 and 6.2.2 also fix this issue, but that is limited to non-Windows environments due to a path separator resolution bug fixed in 5.19.4 and 6.2.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h2h4-5m64-m273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2124</id>
    <title>OESA-2026-2124 — activemq security update</title>
    <updated>2026-10-03T03:15:21.607035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: activemq</p>
<p>The most popular and powerful open source messaging and Integration Patterns server.

Security Fix(es):</p>
<p>[&amp;apos;Severity: low \n\nAffected versions:\n\n- Apache ActiveMQ Client (org.apache.activemq:activemq-client) before 5.19.3\n- Apache ActiveMQ Client (org.apache.activemq:activemq-client) 6.0.0 before 6.2.2\n- Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) before 5.19.3\n- Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) 6.0.0 before 6.2.2\n- Apache ActiveMQ (org.apache.activemq:activemq-all) before 5.19.3\n- Apache ActiveMQ (org.apache.activemq:activemq-all) 6.0.0 before 6.2.2\n- Apache ActiveMQ Web (org.apache.activemq:activemq-web) before 5.19.3\n- Apache ActiveMQ Web (org.apache.activemq:activemq-web) 6.0.0 before 6.2.2\n\nDescription:\n\nImproper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ \nBroker, Apache ActiveMQ All.\n\nIn two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user \nprovided &amp;quot;key&amp;quot; value could be constructed to traverse the classpath due to path concatenation. As a result, the \napplication is exposed to a classpath path resource loading vulnerability that could potentially be chained together \nwith another attack to lead to exploit.This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before \n6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache Activ…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2124"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33227</id>
    <title>UBUNTU-CVE-2026-33227</title>
    <updated>2026-10-03T03:15:21.607084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq, Ubuntu:24.04:LTS: activemq, Ubuntu:25.10: activemq, Ubuntu:26.04:LTS: activemq</p>
<p>Improper validation and restriction of a classpath path name vulnerability in  Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit. This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Web: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ: before 5.19.3, from 6.0.0 before 6.2.2. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note: 5.19.3 and 6.2.2 also fix this issue, but that is limited to non-Windows environments due to a path separator resolution bug fixed in 5.19.4 and 6.2.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33227"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0991</id>
    <title>WID-SEC-W-2026-0991 — Apache ActiveMQ, Client, Broker und Web: Mehrere Schwachstellen</title>
    <updated>2026-10-03T03:15:21.607118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Apache ActiveMQ ausnutzen, um Dateien zu manipulieren oder beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0991"/>
  </entry>
</feed>
