<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:55:00.924295+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</id>
    <title>certfr-2026-avi-1256 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T16:55:01.093010+00:00</updated>
    <content>certfr-2026-avi-1256</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</id>
    <title>Withdrawn: CLEANSTART-2026-AM39668 — yawkat LZ4 Java provides LZ4 compression for Java</title>
    <updated>2026-10-02T16:55:01.093080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-nifi</p>
<p>Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355102</id>
    <title>EUVD-2026-355102</title>
    <updated>2026-10-02T16:55:01.093139+00:00</updated>
    <content>EUVD-2026-355102</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59949</id>
    <title>fkie_cve-2026-59949</title>
    <updated>2026-10-02T16:55:01.093167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xx22-p4ch-683r</id>
    <title>GHSA-xx22-p4ch-683r — LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges</title>
    <updated>2026-10-02T16:55:01.093207+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: at.yawk.lz4:lz4-java, Maven: org.lz4:lz4-java</p>
<p>### Summary</p>
<p>Insufficient validation of byte array arguments in JNI-based XXHash implementations in lz4-java 1.11.0 and earlier allows callers to crash the JVM by passing an invalid array reference or invalid range to native XXHash methods.</p>
<p>This affects applications where an attacker can influence the byte array object or the `off` / `len` arguments passed to affected XXHash APIs. It does **not** affect the common case where only the contents of a valid byte array are attacker-controlled.</p>
<p>Java-based XXHash implementations are *not* affected.</p>
<p>### Details</p>
<p>The JNI-backed XXHash implementations pass caller-provided byte array arguments to native code. The affected APIs are:</p>
<p>- `XXHashFactory.nativeInstance().hash32().hash(byte[] buf, int off, int len, int seed)`
- `XXHashFactory.nativeInstance().hash64().hash(byte[] buf, int off, int len, long seed)`
- `XXHashFactory.nativeInstance().newStreamingHash32(seed).update(byte[] bytes, int off, int len)`
- `XXHashFactory.nativeInstance().newStreamingHash64(seed).update(byte[] bytes, int off, int len)`</p>
<p>Before the fix, the streaming JNI implementations did not validate `bytes`, `off`, or `len` before calling `XXHashJNI.XXH32_update` / `XXHashJNI.XXH64_update`. The non-streaming JNI implementations called `SafeUtils.checkRange`, but `SafeUtils.checkRange(byte[], int, int)` skipped all array access when `len == 0`, so a null byte array with a zero length could still reach JNI.</p>
<p>As a result:</p>
<p>- `hash(null, 0, 0, seed)` and `update(null…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xx22-p4ch-683r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4077</id>
    <title>OESA-2026-4077 — lz4-java security update</title>
    <updated>2026-10-02T16:55:01.093342+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: lz4-java</p>
<p>LZ4 compression for Java, based on Yann Collet&amp;amp;apos;s work. This library provides access to two compression methods that both generate a valid LZ4 stream: * fast scan (LZ4):     ° low memory footprint (~ 16 KB),     ° very fast (fast scan with skipping heuristics in case the       input looks incompressible),     ° reasonable compression ratio (depending on the       redundancy of the input). * high compression (LZ4 HC):     ° medium memory footprint (~ 256 KB),     ° rather slow (~ 10 times slower than LZ4),     ° good compression ratio (depending on the size and       the redundancy of the input). The streams produced by those 2 compression algorithms use the same compression format, are very fast to decompress and can be decompressed by the same decompressor instance.

Security Fix(es):</p>
<p>yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.(CVE-2026-59949)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59949</id>
    <title>UBUNTU-CVE-2026-59949</title>
    <updated>2026-10-02T16:55:01.093378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: lz4-java, Ubuntu:22.04:LTS: lz4-java, Ubuntu:24.04:LTS: lz4-java, Ubuntu:26.04:LTS: lz4-java</p>
<p>yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3595</id>
    <title>WID-SEC-W-2026-3595 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:55:01.093406+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3595"/>
  </entry>
</feed>
