<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:34:12.044205+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</id>
    <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T22:34:12.162382+00:00</updated>
    <content>certfr-2026-avi-1165</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ab17721</id>
    <title>Withdrawn: CLEANSTART-2026-AB17721 — Security fixes in solr 10.0.0-r6</title>
    <updated>2026-10-02T22:34:12.162427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: solr</p>
<p>Package solr version 10.0.0-r6 fixes 4 vulnerabilities: CVE-2026-8384, CVE-2026-6790, CVE-2026-10051, CVE-2026-10050</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ab17721"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336255</id>
    <title>EUVD-2026-336255</title>
    <updated>2026-10-02T22:34:12.162461+00:00</updated>
    <content>EUVD-2026-336255</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8384</id>
    <title>fkie_cve-2026-8384</title>
    <updated>2026-10-02T22:34:12.162474+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In Eclipse Jetty, an HTTP URI of this form:</p>
<p>/public;/../admin/secret.txt</p>
<p>results in an unresolved path of:</p>
<p>/public/../admin/secret.txt</p>
<p>instead of the expected:</p>
<p>/admin/secret.txt</p>
<p>Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served).</p>
<p>However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-8384"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w7x5-g22v-xqhr</id>
    <title>GHSA-w7x5-g22v-xqhr — Eclipse Jetty: Path parameter traversal</title>
    <updated>2026-10-02T22:34:12.162505+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.eclipse.jetty:jetty-util</p>
<p>### Description (as reported)</p>
<p>#### Summary</p>
<p>In Jetty 12.1.8, org.eclipse.jetty.util.URIUtil.canonicalPath() may leave dot-dot path segments unnormalized when a semicolon path parameter marker is followed by a slash and a dot
  segment.</p>
<p>A minimal example is:</p>
<p>`/public;/../admin/secret`</p>
<p>In my local reproduction, URIUtil.canonicalPath() returns:</p>
<p>`/public/../admin/secret`</p>
<p>instead of the expected normalized path:</p>
<p>`/admin/secret`</p>
<p>When Jetty's `SecurityHandler.PathMapped` is used to protect a path prefix such as `/admin/*`, the non-normalized canonical path may not match the protected prefix. As a result, an unauthenticated request may bypass the configured path-based security constraint.</p>
<p>#### Tested Version</p>
<p>Jetty: 12.1.8
JDK: 17.0.18
Maven: 3.9.14</p>
<p>Maven artifacts used:</p>
<p>org.eclipse.jetty:jetty-server:12.1.8
  org.eclipse.jetty:jetty-security:12.1.8
  org.eclipse.jetty:jetty-session:12.1.8</p>
<p>Only confirmed Jetty 12.1.8 so far.</p>
<p>#### Minimal Reproduction</p>
<p>Starts a minimal Jetty server with the following security setup:</p>
<p>```java
SecurityHandler.PathMapped security = new SecurityHandler.PathMapped();
security.put("/admin/*", Constraint.from("admin"));
security.put("/*", Constraint.ALLOWED);
security.setAuthenticator(new BasicAuthenticator());
```</p>
<p>The test then sends requests with no `Authorization` header.</p>
<p>Observed result:</p>
<p>```
GET /admin/secret                  -&gt; 401
GET /public;x/../admin/secret      -&gt; 200
```</p>
<p>The handler receives paths such as:</p>
<p>`/public/../admi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w7x5-g22v-xqhr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8384</id>
    <title>UBUNTU-CVE-2026-8384</title>
    <updated>2026-10-02T22:34:12.162573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: jetty9, Ubuntu:18.04:LTS: jetty9, Ubuntu:20.04:LTS: jetty9, Ubuntu:22.04:LTS: jetty9, Ubuntu:24.04:LTS: jetty9, Ubuntu:26.04:LTS: jetty12, Ubuntu:26.04:LTS: jetty9</p>
<p>In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served). However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8384"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2314</id>
    <title>WID-SEC-W-2026-2314 — Eclipse Jetty: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:34:12.162653+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2314"/>
  </entry>
</feed>
