<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T01:13:52.883429+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-40975</id>
    <title>CVE-2026-40975</title>
    <updated>2026-10-06T01:13:52.884705+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Spring Boot, Red Hat HawtIO HawtIO 4.4.0, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat Data Grid 8.6.1, Red Hat OpenShift Dev Spaces 3.28, Red Hat AMQ Broker 7, Red Hat AMQ Clients, Red Hat build of OptaPlanner 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 and 6 more</p>
<p>Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range.</p>
<p>Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-40975"/>
  </entry>
</feed>
