<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T17:46:51.709166+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0739</id>
    <title>certfr-2026-avi-0739 — De multiples vulnérabilités ont été découvertes dans les produits Spring. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-08T17:46:51.759530+00:00</updated>
    <content>certfr-2026-avi-0739</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0739"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329699</id>
    <title>EUVD-2026-329699</title>
    <updated>2026-10-08T17:46:51.759574+00:00</updated>
    <content>EUVD-2026-329699</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40999</id>
    <title>fkie_cve-2026-40999</title>
    <updated>2026-10-08T17:46:51.759588+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to.</p>
<p>Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-whpp-xv3h-rwxf</id>
    <title>GHSA-whpp-xv3h-rwxf — Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations</title>
    <updated>2026-10-08T17:46:51.759620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.springframework.ws:spring-ws-core</p>
<p>When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to.</p>
<p>Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-whpp-xv3h-rwxf"/>
  </entry>
</feed>
