<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T19:25:34.055385+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-1225</id>
    <title>CVE-2026-1225 — Malicious logback.xml configuration file allows instantiation of arbitrary classes</title>
    <updated>2026-10-04T19:25:34.134849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> QOS.CH Sarl Logback-core</p>
<p>ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.</p>
<p>The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must  have write access to a 
configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-1225"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4773-3jfm-qmx3</id>
    <title>GHSA-4773-3jfm-qmx3 — Spring Framework Improper Path Limitation with Script View Templates</title>
    <updated>2026-10-04T19:25:34.134914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.springframework:spring-webmvc, Maven: org.springframework:spring-webflux</p>
<p>Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4773-3jfm-qmx3"/>
  </entry>
</feed>
