<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:36:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-00439</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-00439</link>
      <description>bdu:2019-00439</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-00439</guid>
    </item>
    <item>
      <title>cnvd-2018-06100</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-06100</link>
      <description>cnvd-2018-06100</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-06100</guid>
    </item>
    <item>
      <title>EUVD-2026-71103</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-71103</link>
      <description>EUVD-2026-71103</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-71103</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1000119</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000119</link>
      <description>&lt;p&gt;Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000119</guid>
    </item>
    <item>
      <title>GHSA-688c-3x49-6rqj — rack-protection gem timing attack vulnerability when validating CSRF token</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-688c-3x49-6rqj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rack-protection&lt;/p&gt;
&lt;p&gt;Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rack-protection&lt;/p&gt;
&lt;p&gt;Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-688c-3x49-6rqj</guid>
    </item>
    <item>
      <title>gsd-2018-1000119</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1000119</link>
      <description>gsd-2018-1000119</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1000119</guid>
    </item>
    <item>
      <title>RHSA-2018:1060 — Red Hat Security Advisory: pcs security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:1060</link>
      <description>&lt;p&gt;pcs: Privilege escalation via authorized user malicious REST call pcs: Debug parameter removal bypass, allowing information disclosure rack-protection: Timing attack in authenticity_token.rb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pcs: Privilege escalation via authorized user malicious REST call pcs: Debug parameter removal bypass, allowing information disclosure rack-protection: Timing attack in authenticity_token.rb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:1060</guid>
    </item>
    <item>
      <title>RHSA-2020:4366 — Red Hat Security Advisory: Satellite 6.8 release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4366</link>
      <description>&lt;p&gt;mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018) puppet-agent: Puppet Agent does not properly verify SSL connection when downloading a CRL rack-protection: Timing attack in authenticity_token.rb hibernate-validator: safeHTML validator allows XSS Django: Incorrect HTTP detection with reverse-proxy connecting via HTTPS rubygem-rack: hijack sessions by using timing attacks targeting the session id rubygem-secure_headers: limited header injection when using dynamic overrides with user input rubygem-secure_headers: directive injection when using dynamic overrides with user input rubygem-actionview: views that use the `j` or `escape_javascript` methods are susceptible to XSS attacks netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling rubygem-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser puppet: Arbitrary catalog retrieval puppet: puppet server and puppetDB may leak sensitive information via metrics API rubygem-rack: directory traversal in Rack::Directory rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie names jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core hibernate-validator: Improper input validation in the interpolation of constraint error messages jackson-databind: Ser…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018) puppet-agent: Puppet Agent does not properly verify SSL connection when downloading a CRL rack-protection: Timing attack in authenticity_token.rb hibernate-validator: safeHTML validator allows XSS Django: Incorrect HTTP detection with reverse-proxy connecting via HTTPS rubygem-rack: hijack sessions by using timing attacks targeting the session id rubygem-secure_headers: limited header injection when using dynamic overrides with user input rubygem-secure_headers: directive injection when using dynamic overrides with user input rubygem-actionview: views that use the `j` or `escape_javascript` methods are susceptible to XSS attacks netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling rubygem-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser puppet: Arbitrary catalog retrieval puppet: puppet server and puppetDB may leak sensitive information via metrics API rubygem-rack: directory traversal in Rack::Directory rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie names jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core hibernate-validator: Improper input validation in the interpolation of constraint error messages jackson-databind: Ser…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4366</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-1000119</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000119</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-rack-protection, Ubuntu:18.04:LTS: ruby-rack-protection&lt;/p&gt;
&lt;p&gt;Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-rack-protection, Ubuntu:18.04:LTS: ruby-rack-protection&lt;/p&gt;
&lt;p&gt;Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000119</guid>
    </item>
  </channel>
</rss>
