<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T05:10:48.731765+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-5996</id>
    <title>EUVD-2026-5996</title>
    <updated>2026-10-07T05:10:48.733985+00:00</updated>
    <content>EUVD-2026-5996</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-5996"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38374</id>
    <title>fkie_cve-2024-38374</title>
    <updated>2026-10-07T05:10:48.734016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the schema version of the BOM. The `DocumentBuilderFactory` used to evaluate XPath expressions was not configured securely, making the library vulnerable to XML External Entity (XXE) injection. This vulnerability has been fixed in cyclonedx-core-java version 9.0.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-38374"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-683x-4444-jxh8</id>
    <title>GHSA-683x-4444-jxh8 — Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java</title>
    <updated>2026-10-07T05:10:48.734049+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.cyclonedx:cyclonedx-core-java</p>
<p>### Impact</p>
<p>Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the schema version of the BOM. The `DocumentBuilderFactory` used to evaluate XPath expressions was not configured securely, making the library vulnerable to XML External Entity (XXE) injection.</p>
<p>XXE injection can be exploited to exfiltrate local file content, or perform Server Side Request Forgery (SSRF) to access infrastructure adjacent to the vulnerable application.</p>
<p>### PoC</p>
<p>```java
import org.cyclonedx.parsers.XmlParser;</p>
<p>class Poc {</p>
<p>public static void main(String[] args) {
        // Will throw org.cyclonedx.exception.ParseException: java.net.ConnectException: Connection refused
        new XmlParser().parse("""
            &lt;?xml version="1.0" encoding="UTF-8"?&gt;
            &lt;!DOCTYPE bom [&lt;!ENTITY % sp SYSTEM "https://localhost:1010/does-not-exist/file.dtd"&gt; %sp;]&gt;
            &lt;bom xmlns="http://cyclonedx.org/schema/bom/1.5"/&gt;
            """.getBytes());
    }</p>
<p>}
```</p>
<p>### Patches</p>
<p>The vulnerability has been fixed in _cyclonedx-core-java_ version 0.9.4.</p>
<p>### Workarounds</p>
<p>If feasible, applications can reject XML documents before handing them to _cyclonedx-core-java_ for parsing.
This may be an option if incoming CycloneDX BOMs are known to be in JSON format.</p>
<p>### References</p>
<p>* Issue was fixed via &lt;https://github.com/CycloneDX/cyclonedx-core-java/pull/434&gt;
* Issue was introduced via &lt;https://github.com/CycloneDX/cyclonedx-core-jav…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-683x-4444-jxh8"/>
  </entry>
</feed>
