<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:20:03.492164+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335238</id>
    <title>EUVD-2026-335238</title>
    <updated>2026-10-03T22:20:03.567896+00:00</updated>
    <content>EUVD-2026-335238</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335238"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55471</id>
    <title>fkie_cve-2026-55471</title>
    <updated>2026-10-03T22:20:03.567945+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET restrictions, allowing an attacker who controls or can tamper with transformed XML to trigger XML External Entity injection for local file disclosure and blind XXE or SSRF to arbitrary URLs reachable from the host. This issue is fixed in version 6.9.10.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2f55-g35j-5jmf</id>
    <title>GHSA-2f55-g35j-5jmf — HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory</title>
    <updated>2026-10-03T22:20:03.567993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: ca.uhn.hapi.fhir:org.hl7.fhir.utilities</p>
<p>### Summary</p>
<p>`org.hl7.fhir.utilities.XsltUtilities` exposes two parallel families of XSLT
transform helpers. The `transform(...)` overloads obtain their
`TransformerFactory` from the project's hardened helper
`XMLUtil.newXXEProtectedTransformerFactory()` (which sets
`ACCESS_EXTERNAL_DTD=""` and `ACCESS_EXTERNAL_STYLESHEET=""`). The sibling
`saxonTransform(...)` overloads instead instantiate a **bare**
`new net.sf.saxon.TransformerFactoryImpl()` with no external-access
restriction. A document transformed through any `saxonTransform(...)` overload
is parsed with external general entities and external DTD/parameter entities
enabled, so an attacker who controls (or can MITM) the transformed XML obtains
XML External Entity injection: local file disclosure and blind XXE / SSRF to
arbitrary URLs reachable from the host.</p>
<p>`XMLUtil` documents that its protected factory "should be the only place where
TransformerFactory is instantiated in this project". The `saxonTransform`
overloads violate that contract while their same-file `transform` siblings
honour it.</p>
<p>### Affected versions</p>
<p>`org.hl7.fhir.utilities` (Maven `ca.uhn.hapi.fhir:org.hl7.fhir.utilities`)
`&lt;= 6.9.8` (latest release at time of report; verified live on `6.9.8`).
The bare `net.sf.saxon.TransformerFactoryImpl()` instantiation is present at
`XsltUtilities.java:61`, `:91`, and `:106`.</p>
<p>### Privilege required</p>
<p>None at the library boundary. The exposure depends on the calling tool: any
FHIR component that runs `XsltUtilities.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2f55-g35j-5jmf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:54776</id>
    <title>RHSA-2026:54776 — Red Hat Security Advisory: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.3.GA)</title>
    <updated>2026-10-03T22:20:03.568168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data ca.uhn.hapi.fhir/org.hl7.fhir.dstu2: ca.uhn.hapi.fhir/org.hl7.fhir.convertors: ca.uhn.hapi.fhir/org.hl7.fhir.validation: ca.uhn.hapi.fhir/org.hl7.fhir.validation.cli: HAPI FHIR: Denial of Service via Regular Expression Backtracking in DSTU2 Module ca.uhn.hapi.fhir/org.hl7.fhir.utilities: HAPI FHIR XsltUtilities: XML External Entity injection allows local file disclosure and SSRF org.apache.sshd/sshd-core: Apache MINA SSHD: Unauthorized command execution due to improper certificate validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:54776"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2834</id>
    <title>WID-SEC-W-2026-2834 — Red Hat Build of Apache Camel for Quarkus (sshd-core, libthrift, org.hl7.fhir.utilities): Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:20:03.568215+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Apache Camel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und offenzulegen oder beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2834"/>
  </entry>
</feed>
