<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T08:34:54.945054+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265586</id>
    <title>EUVD-2026-265586</title>
    <updated>2026-10-06T08:34:54.947772+00:00</updated>
    <content>EUVD-2026-265586</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68703</id>
    <title>fkie_cve-2025-68703</title>
    <updated>2026-10-06T08:34:54.947804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with the same password will have the same derived key. This vulnerability is fixed in 2.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-36h5-vrq6-pp34</id>
    <title>GHSA-36h5-vrq6-pp34 — Jervis's Salt for PBKDF2 derived from password</title>
    <updated>2026-10-06T08:34:54.947833+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: net.gleske:jervis</p>
<p>### Vulnerability</p>
<p>https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L869-L870</p>
<p>https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L894-L895</p>
<p>The salt is derived from sha256Sum(passphrase).  Two encryption operations with the same password will have the same derived key.</p>
<p>### Impact</p>
<p>Pre-computation attacks.</p>
<p>Severity is considered low for internal uses of this library and high for consumers of this library.</p>
<p>### Patches</p>
<p>Jervis will generate a random salt for each password and store it alongside the ciphertext.</p>
<p>Upgrade to Jervis 2.2.</p>
<p>### Workarounds</p>
<p>None</p>
<p>### References</p>
<p>- [NIST SP 800-132: Password-Based Key Derivation](https://csrc.nist.gov/publications/detail/sp/800-132/final)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-36h5-vrq6-pp34"/>
  </entry>
</feed>
