<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T21:45:06.732716+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0739</id>
    <title>certfr-2026-avi-0739 — De multiples vulnérabilités ont été découvertes dans les produits Spring. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-06T21:45:06.779497+00:00</updated>
    <content>certfr-2026-avi-0739</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0739"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329698</id>
    <title>EUVD-2026-329698</title>
    <updated>2026-10-06T21:45:06.779539+00:00</updated>
    <content>EUVD-2026-329698</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40998</id>
    <title>fkie_cve-2026-40998</title>
    <updated>2026-10-06T21:45:06.779554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks.</p>
<p>Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40998"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2mpf-m756-hxjm</id>
    <title>GHSA-2mpf-m756-hxjm — Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource</title>
    <updated>2026-10-06T21:45:06.779587+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.springframework.ws:spring-xml</p>
<p>Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks.</p>
<p>Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2mpf-m756-hxjm"/>
  </entry>
</feed>
