<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:33:09.362157+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ba48144</id>
    <title>Withdrawn: CLEANSTART-2026-BA48144 — Security fixes in keycloak 26.5.7-r5</title>
    <updated>2026-10-03T13:33:09.494779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: keycloak</p>
<p>Package keycloak version 26.5.7-r5 fixes 11 vulnerabilities: CVE-2026-54291, CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ba48144"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351886</id>
    <title>EUVD-2026-351886</title>
    <updated>2026-10-03T13:33:09.494839+00:00</updated>
    <content>EUVD-2026-351886</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50559</id>
    <title>fkie_cve-2026-50559</title>
    <updated>2026-10-03T13:33:09.494855+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qcxp-gm7m-4j5v</id>
    <title>GHSA-qcxp-gm7m-4j5v — Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities</title>
    <updated>2026-10-03T13:33:09.494882+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.quarkus:quarkus-vertx-http</p>
<p>Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix
  parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static
  resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping.</p>
<p>### Technical Details</p>
<p>The security layer (AbstractPathMatchingHttpSecurityPolicy) normalizes request paths using Vert.x's normalizedPath(),
  which only decodes unreserved RFC 3986 characters (letters, digits, -, ., _, ~). It then strips matrix parameters by
  looking for literal ; characters. This creates two mismatches:</p>
<p>1. Encoded semicolons (`%3B`): Since `%3B` is not decoded by normalizedPath(), the matrix parameter stripping in
  pathWithoutMatrixParams() never sees it. The encoded semicolon and everything after it become part of the path
  segment, causing policy matching to fail. This affects all path-policy-protected endpoints.
  2. Static resource path mismatch: Static resource handlers (StaticHandlerImpl, FileSystemStaticHandler) perform full
  percent-decoding via URIDecoder.decodeURIComponent() and backslash-to-slash conversion before filesystem resolution.
  Reserved characters like `%2F` (slash) and `%5C` (backslash) that survive the security layer's partial decoding are fully
  decoded before file serving.</p>
<p>REST endpoints using Quarkus REST (RESTEasy Reactive) are not affected by the `%2F/%5C` vectors because the rou…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qcxp-gm7m-4j5v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:26017</id>
    <title>RHSA-2026:26017 — Red Hat Security Advisory: Red Hat build of Quarkus 3.33.2.SP1 security update</title>
    <updated>2026-10-03T13:33:09.494942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>eclipse-vertx/vert.x: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder io.quarkus/quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded characters netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:26017"/>
  </entry>
</feed>
