<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T14:32:08.696441+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1206</id>
    <title>certfr-2026-avi-1206 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T14:32:08.901549+00:00</updated>
    <content>certfr-2026-avi-1206</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-365462</id>
    <title>EUVD-2026-365462</title>
    <updated>2026-10-04T14:32:08.901590+00:00</updated>
    <content>EUVD-2026-365462</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-365462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42027</id>
    <title>fkie_cve-2026-42027</title>
    <updated>2026-10-04T14:32:08.901605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader</p>
<p>Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3</p>
<p>Description:</p>
<p>The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its no-arg constructor, with the class name sourced from the manifest.properties entry of a model archive. The existing isAssignableFrom check correctly rejects classes that are not subtypes of the expected extension interface (BaseToolFactory for factory=, ArtifactSerializer for serializer-class-*), but the check runs after Class.forName() has already loaded and initialized the named class.</p>
<p>Class.forName() with default initialization semantics executes the target class's static initializer before returning, so an attacker who can supply a crafted model archive can cause the static initializer of any class on the classpath to run during model loading, regardless of whether that class passes the subsequent type check.</p>
<p>Exploitation requires a class with attacker-useful side effects in its static initializer (for example, JNDI lookup, outbound network I/O, or filesystem access) to be present on the classpath, so this is not a drop-in remote code execution; however, the attack surface grows as third-party model distribution becomes more common (community model repositories, Hugging Face-style sharing), where users routinely load model files from origins they do not control…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cx4m-2p55-rw7j</id>
    <title>GHSA-cx4m-2p55-rw7j — Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest</title>
    <updated>2026-10-04T14:32:08.901660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.opennlp:opennlp-tools</p>
<p>Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3</p>
<p>Description:</p>
<p>The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its no-arg constructor, with the class name sourced from the manifest.properties entry of a model archive. The existing isAssignableFrom check correctly rejects classes that are not subtypes of the expected extension interface (BaseToolFactory for factory=, ArtifactSerializer for serializer-class-*), but the check runs after Class.forName() has already loaded and initialized the named class.</p>
<p>Class.forName() with default initialization semantics executes the target class's static initializer before returning, so an attacker who can supply a crafted model archive can cause the static initializer of any class on the classpath to run during model loading, regardless of whether that class passes the subsequent type check.</p>
<p>Exploitation requires a class with attacker-useful side effects in its static initializer (for example, JNDI lookup, outbound network I/O, or filesystem access) to be present on the classpath, so this is not a drop-in remote code execution; however, the attack surface grows as third-party model distribution becomes more common (community model repositories, Hugging Face-style sharing), where users routinely load model files from origins they do not control. A secondary, narrower vector affects deployments that ship legitimate BaseToolFactory or A…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cx4m-2p55-rw7j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11281-1</id>
    <title>openSUSE-SU-2026:11281-1 — opennlp-1.9.5-1.1 on GA media</title>
    <updated>2026-10-04T14:32:08.901707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>opennlp-1.9.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11281-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:65126</id>
    <title>RHSA-2026:65126 — Red Hat Security Advisory: RHOAI 2.25.11 - Red Hat OpenShift AI</title>
    <updated>2026-10-04T14:32:08.901729+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing org.eclipse.parsson/parsson: Eclipse Parsson: Denial of Service via uncontrolled resource consumption in JSON parsing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames nltk: NLTK: Information disclosure via path traversal vulnerability brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex guardrails-detectors: guardrails-detectors: SSRF and local file read via user-supplied XML Schema (xml-with-schema:) trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation data-science-pipelines-operator: DSPO: Operator ClusterRole grants…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:65126"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42027</id>
    <title>UBUNTU-CVE-2026-42027</title>
    <updated>2026-10-04T14:32:08.901959+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: apache-opennlp, Ubuntu:22.04:LTS: apache-opennlp, Ubuntu:24.04:LTS: apache-opennlp, Ubuntu:25.10: apache-opennlp, Ubuntu:26.04:LTS: apache-opennlp</p>
<p>Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its no-arg constructor, with the class name sourced from the manifest.properties entry of a model archive. The existing isAssignableFrom check correctly rejects classes that are not subtypes of the expected extension interface (BaseToolFactory for factory=, ArtifactSerializer for serializer-class-*), but the check runs after Class.forName() has already loaded and initialized the named class. Class.forName() with default initialization semantics executes the target class's static initializer before returning, so an attacker who can supply a crafted model archive can cause the static initializer of any class on the classpath to run during model loading, regardless of whether that class passes the subsequent type check. Exploitation requires a class with attacker-useful side effects in its static initializer (for example, JNDI lookup, outbound network I/O, or filesystem access) to be present on the classpath, so this is not a drop-in remote code execution; however, the attack surface grows as third-party model distribution becomes more common (community model repositories, Hugging Face-style sharing), where users routinely load model files from origins they do not control. A secondary, n…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42027"/>
  </entry>
</feed>
