<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:08:23.652228+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265585</id>
    <title>EUVD-2026-265585</title>
    <updated>2026-10-06T22:08:23.700665+00:00</updated>
    <content>EUVD-2026-265585</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265585"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68704</id>
    <title>fkie_cve-2025-68704</title>
    <updated>2026-10-06T22:08:23.700704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68704"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c9q6-g3hr-8gww</id>
    <title>GHSA-c9q6-g3hr-8gww — Jervis Has Weak Random for Timing Attack Mitigation</title>
    <updated>2026-10-06T22:08:23.700737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: net.gleske:jervis</p>
<p>### Vulnerability</p>
<p>https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L593-L594</p>
<p>Uses `java.util.Random()` which is not cryptographically secure.</p>
<p>### Impact</p>
<p>If an attacker can predict the random delays, they may still be able to perform timing attacks.</p>
<p>### Patches</p>
<p>Jervis will use `SecureRandom` for timing randomization.</p>
<p>Upgrade to Jervis 2.2.</p>
<p>### Workarounds</p>
<p>None</p>
<p>### References</p>
<p>- [OWASP Cryptographic Failures](https://owasp.org/Top10/A02_2021-Cryptographic_Failures/)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c9q6-g3hr-8gww"/>
  </entry>
</feed>
