<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:39:36 +0000</lastBuildDate>
    <item>
      <title>BREW-travis-CVE-2013-1856 — activesupport Improper Input Validation vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/brew-travis-cve-2013-1856</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: travis&lt;/p&gt;
&lt;p&gt;The `ActiveSupport::XmlMini_JDOM` backend in `lib/active_support/xml_mini/jdom.rb` in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: travis&lt;/p&gt;
&lt;p&gt;The `ActiveSupport::XmlMini_JDOM` backend in `lib/active_support/xml_mini/jdom.rb` in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-travis-cve-2013-1856</guid>
    </item>
    <item>
      <title>certa-2013-avi-193 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Ruby on Rails&lt;/span&gt;. Elles permettent à un att…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2013-avi-193</link>
      <description>certa-2013-avi-193</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2013-avi-193</guid>
    </item>
    <item>
      <title>EUVD-2026-105684</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-105684</link>
      <description>EUVD-2026-105684</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-105684</guid>
    </item>
    <item>
      <title>fkie_cve-2013-1856</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2013-1856</link>
      <description>&lt;p&gt;The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2013-1856</guid>
    </item>
    <item>
      <title>GHSA-9c2j-593q-3g82 — activesupport Improper Input Validation vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9c2j-593q-3g82</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: activesupport&lt;/p&gt;
&lt;p&gt;The `ActiveSupport::XmlMini_JDOM` backend in `lib/active_support/xml_mini/jdom.rb` in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: activesupport&lt;/p&gt;
&lt;p&gt;The `ActiveSupport::XmlMini_JDOM` backend in `lib/active_support/xml_mini/jdom.rb` in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9c2j-593q-3g82</guid>
    </item>
    <item>
      <title>gsd-2013-1856</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2013-1856</link>
      <description>gsd-2013-1856</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2013-1856</guid>
    </item>
  </channel>
</rss>
