<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:33:40 +0000</lastBuildDate>
    <item>
      <title>cnvd-2018-15547</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-15547</link>
      <description>cnvd-2018-15547</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-15547</guid>
    </item>
    <item>
      <title>EUVD-2026-179759</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-179759</link>
      <description>EUVD-2026-179759</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-179759</guid>
    </item>
    <item>
      <title>fkie_cve-2018-8020</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-8020</link>
      <description>&lt;p&gt;Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-8020</guid>
    </item>
    <item>
      <title>GHSA-r94v-7v68-9rjq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r94v-7v68-9rjq</link>
      <description>&lt;p&gt;Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r94v-7v68-9rjq</guid>
    </item>
    <item>
      <title>gsd-2018-8020</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-8020</link>
      <description>gsd-2018-8020</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-8020</guid>
    </item>
    <item>
      <title>RHSA-2018:2469 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.1.0 Service Pack 4 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2469</link>
      <description>&lt;p&gt;tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins tomcat-native: Mishandled OCSP invalid response tomcat-native: Mishandled OCSP responses can allow clients to authenticate with revoked certificates&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: Insecure defaults in CORS filter enable &amp;#39;supportsCredentials&amp;#39; for all origins tomcat-native: Mishandled OCSP invalid response tomcat-native: Mishandled OCSP responses can allow clients to authenticate with revoked certificates&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2469</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:14014-1 — Security update for libtcnative-1-0</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:14014-1</link>
      <description>&lt;p&gt;Security update for libtcnative-1-0&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libtcnative-1-0&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:14014-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-8020</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-8020</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: tomcat-native&lt;/p&gt;
&lt;p&gt;Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: tomcat-native&lt;/p&gt;
&lt;p&gt;Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-8020</guid>
    </item>
  </channel>
</rss>
