<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T06:11:16.224542+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-59250</id>
    <title>CVE-2025-59250 — JDBC Driver for SQL Server Spoofing Vulnerability</title>
    <updated>2026-10-05T06:11:16.456065+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Microsoft JDBC Driver for SQL Server 10.2, Microsoft JDBC Driver for SQL Server 11.2, Microsoft JDBC Driver for SQL Server 12.10, Microsoft JDBC Driver for SQL Server 12.2, Microsoft JDBC Driver for SQL Server 12.4, Microsoft JDBC Driver for SQL Server 12.6, Microsoft JDBC Driver for SQL Server 12.8, Microsoft JDBC Driver for SQL Server 13.2</p>
<p>Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-59250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2m67-wjpj-xhg9</id>
    <title>GHSA-2m67-wjpj-xhg9 — Jackson Core: Document length constraint bypass in blocking, async, and DataInput parsers</title>
    <updated>2026-10-05T06:11:16.456132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: tools.jackson.core:jackson-core</p>
<p>## Summary</p>
<p>Jackson Core 3.x does not consistently enforce `StreamReadConstraints.maxDocumentLength`. Oversized JSON documents can be accepted without a `StreamConstraintsException` in multiple parser entry points, which allows configured size limits to be bypassed and weakens denial-of-service protections.</p>
<p>## Details</p>
<p>Three code paths where `maxDocumentLength` is not fully enforced:</p>
<p>### 1. Blocking parsers skip validation of the final in-memory buffer</p>
<p>Blocking parsers validate only previously processed buffers, not the final in-memory buffer:</p>
<p>- `ReaderBasedJsonParser.java:255`
- `UTF8StreamJsonParser.java:208`</p>
<p>Relevant code:</p>
<p>```java
_currInputProcessed += bufSize;
_streamReadConstraints.validateDocumentLength(_currInputProcessed);
```</p>
<p>This means the check occurs only when a completed buffer is rolled over. If an oversized document is fully contained in the final buffer, parsing can complete without any document-length exception.</p>
<p>### 2. Async parsers skip validation of the final chunk on end-of-input</p>
<p>Async parsers validate previously processed chunks, but do not validate the final chunk on end-of-input:</p>
<p>- `NonBlockingByteArrayJsonParser.java:49`
- `NonBlockingByteBufferJsonParser.java:57`
- `NonBlockingUtf8JsonParserBase.java:75`</p>
<p>Relevant code:</p>
<p>```java
_currInputProcessed += _origBufferLen;
_streamReadConstraints.validateDocumentLength(_currInputProcessed);</p>
<p>public void endOfInput() {
    _endOfInput = true;
}
```</p>
<p>`endOfInput()` marks EOF but does not perform a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2m67-wjpj-xhg9"/>
  </entry>
</feed>
