<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T18:35:17.372440+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-10695</id>
    <title>bdu:2024-10695</title>
    <updated>2026-10-08T18:35:17.381725+00:00</updated>
    <content>bdu:2024-10695</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-10695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-372744</id>
    <title>EUVD-2026-372744</title>
    <updated>2026-10-08T18:35:17.381760+00:00</updated>
    <content>EUVD-2026-372744</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-372744"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-10492</id>
    <title>fkie_cve-2024-10492</title>
    <updated>2026-10-08T18:35:17.381774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example, an LDAP provider configuration and set up a Vault read file, which will only inform whether that file exists or not.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-10492"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5545-r4hg-rj4m</id>
    <title>GHSA-5545-r4hg-rj4m — Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path</title>
    <updated>2026-10-08T18:35:17.381802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-quarkus-server</p>
<p>A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example, an LDAP provider configuration and set up a Vault read file, which will only inform whether that file exists or not.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5545-r4hg-rj4m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:10175</id>
    <title>RHSA-2024:10175 — Red Hat Security Advisory: Red Hat build of Keycloak 24.0.9 Images Update</title>
    <updated>2026-10-08T18:35:17.381827+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.keycloak/keycloak-quarkus-server: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability keycloak-core: mTLS passthrough org.keycloak:keycloak-services: Keycloak Denial of Service org.keycloak:keycloak-quarkus-server: Sensitive Data Exposure in Keycloak Build Process keycloak-quarkus-server: Keycloak path trasversal</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:10175"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3525</id>
    <title>WID-SEC-W-2024-3525 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-08T18:35:17.381848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Keycloak und Red Hat OpenShift ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen preiszugeben und einen Denial-of-Service-Zustand zu erzeugen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3525"/>
  </entry>
</feed>
