<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:57:00.882182+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-08042</id>
    <title>bdu:2023-08042</title>
    <updated>2026-10-02T23:57:01.031422+00:00</updated>
    <content>bdu:2023-08042</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-08042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0860</id>
    <title>certfr-2023-avi-0860 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T23:57:01.031459+00:00</updated>
    <content>certfr-2023-avi-0860</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0860"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216070</id>
    <title>EUVD-2026-216070</title>
    <updated>2026-10-02T23:57:01.031479+00:00</updated>
    <content>EUVD-2026-216070</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216070"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-44729</id>
    <title>fkie_cve-2022-44729</title>
    <updated>2026-10-02T23:57:01.031492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.</p>
<p>On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-44729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gq5f-xv48-2365</id>
    <title>GHSA-gq5f-xv48-2365 — Apache XML Graphics Batik Server-Side Request Forgery vulnerability</title>
    <updated>2026-10-02T23:57:01.031521+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.xmlgraphics:batik-bridge, Maven: org.apache.xmlgraphics:batik-svgrasterizer, Maven: org.apache.xmlgraphics:batik-transcoder</p>
<p>Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.</p>
<p>On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gq5f-xv48-2365"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-44729</id>
    <title>gsd-2022-44729</title>
    <updated>2026-10-02T23:57:01.031550+00:00</updated>
    <content>gsd-2022-44729</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-44729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-261-04</id>
    <title>ICSA-25-261-04 — Multiple Open-Source Software Vulnerabilities in Hitachi Energy Asset Suite Product</title>
    <updated>2026-10-02T23:57:01.031562+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Hitachi Energy is aware of multiple reported vulnerabilities that affect the Asset Suite product versions mentioned in this document below. If exploited these vulnerabilities can potentially impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-261-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1651</id>
    <title>OESA-2023-1651 — batik security update</title>
    <updated>2026-10-02T23:57:01.031584+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: batik, openEuler:20.03-LTS-SP3: batik, openEuler:22.03-LTS: batik, openEuler:22.03-LTS-SP1: batik, openEuler:22.03-LTS-SP2: batik</p>
<p>Batik is an inline templating engine for CoffeeScript, inspired by CoffeeKup,  that lets you write your template directly as a CoffeeScript function.

Security Fix(es):

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.(CVE-2022-38398)

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.(CVE-2022-38648)

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.(CVE-2022-40146)

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.

On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.

(CVE-2022-44729)

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.

A malicious SVG can probe user profile / data and send it directly as parameter to a URL.

(CVE-2022-44730)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13743-1</id>
    <title>openSUSE-SU-2024:13743-1 — xmlgraphics-batik-1.17-1.1 on GA media</title>
    <updated>2026-10-02T23:57:01.031620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xmlgraphics-batik-1.17-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13743-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:5441</id>
    <title>RHSA-2023:5441 — Red Hat Security Advisory: Red Hat Integration Camel for Spring Boot 4.0.0 release and security update</title>
    <updated>2026-10-02T23:57:01.031683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>batik: Server-Side Request Forgery vulnerability batik: Server-Side Request Forgery vulnerability apache-ivy: XML External Entity vulnerability jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies apache-johnzon: Prevent inefficient internal conversion from BigDecimal at large scale netty: SniHandler 16MB allocation leads to OOM jetty: Improper validation of HTTP/1 content-length</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:5441"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:0777-1</id>
    <title>SUSE-SU-2024:0777-1 — Security update for xmlgraphics-batik</title>
    <updated>2026-10-02T23:57:01.031710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for xmlgraphics-batik</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:0777-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-44729</id>
    <title>UBUNTU-CVE-2022-44729</title>
    <updated>2026-10-02T23:57:01.031729+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: batik, Ubuntu:18.04:LTS: batik, Ubuntu:20.04:LTS: batik, Ubuntu:22.04:LTS: batik, Ubuntu:24.04:LTS: batik, Ubuntu:25.10: batik, Ubuntu:26.04:LTS: batik</p>
<p>Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-44729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2673</id>
    <title>WID-SEC-W-2023-2673 — Oracle Database Server: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:57:01.031759+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Database Server ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2673"/>
  </entry>
</feed>
