<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T07:01:27.260634+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-22257</id>
    <title>CVE-2024-22257</title>
    <updated>2026-10-08T07:01:27.376481+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Spring Security, pivotal_software spring_security</p>
<p>In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 
5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, 
versions 6.2.x prior to 6.2.3, an application is possible vulnerable to 
broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-22257"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3677-xxcr-wjqv</id>
    <title>GHSA-3677-xxcr-wjqv — jose4j is vulnerable to DoS via compressed JWE content</title>
    <updated>2026-10-08T07:01:27.376545+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.bitbucket.b_c:jose4j</p>
<p>In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3677-xxcr-wjqv"/>
  </entry>
</feed>
