<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:22:42 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-04803</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-04803</link>
      <description>bdu:2020-04803</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-04803</guid>
    </item>
    <item>
      <title>cnvd-2020-03215</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-03215</link>
      <description>cnvd-2020-03215</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-03215</guid>
    </item>
    <item>
      <title>EUVD-2026-49787</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-49787</link>
      <description>EUVD-2026-49787</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-49787</guid>
    </item>
    <item>
      <title>fkie_cve-2019-3888</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-3888</link>
      <description>&lt;p&gt;A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-3888</guid>
    </item>
    <item>
      <title>GHSA-jwgx-9mmh-684w — Credential exposure through log files in Undertow</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jwgx-9mmh-684w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.undertow:undertow-core&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.undertow:undertow-core&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jwgx-9mmh-684w</guid>
    </item>
    <item>
      <title>gsd-2019-3888</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-3888</link>
      <description>gsd-2019-3888</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-3888</guid>
    </item>
    <item>
      <title>OESA-2021-1422 — undertow security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1422</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: undertow, openEuler:20.03-LTS-SP2: undertow&lt;/p&gt;
&lt;p&gt;Java web server using non-blocking IO&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)(CVE-2019-3888)&#13;
&#13;
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the &amp;amp;quot;Expect: 100-continue&amp;amp;quot; header may cause an out of memory error. This flaw may potentially lead to a denial of service.(CVE-2020-10705)&#13;
&#13;
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.(CVE-2020-10719)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: undertow, openEuler:20.03-LTS-SP2: undertow&lt;/p&gt;
&lt;p&gt;Java web server using non-blocking IO&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)(CVE-2019-3888)&#13;
&#13;
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the &amp;amp;quot;Expect: 100-continue&amp;amp;quot; header may cause an out of memory error. This flaw may potentially lead to a denial of service.(CVE-2020-10705)&#13;
&#13;
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.(CVE-2020-10719)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1422</guid>
    </item>
    <item>
      <title>RHSA-2019:1419 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.2 on RHEL 6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:1419</link>
      <description>&lt;p&gt;picketlink: reflected XSS in SAMLRequest via RelayState parameter picketlink: URL injection via xinclude parameter undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailed&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;picketlink: reflected XSS in SAMLRequest via RelayState parameter picketlink: URL injection via xinclude parameter undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailed&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:1419</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-3888</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-3888</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:20.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:20.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-3888</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1947 — Red Hat Single Sign On: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1947</link>
      <description>&lt;p&gt;Ein  Angreifer kann mehrere Schwachstellen in Red Hat Single Sign On ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, einen Denial of Service Zustand hervorzurufen, Informationen auszuspähen, Sicherheitsvorkehrungen zu umgehen oder beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein  Angreifer kann mehrere Schwachstellen in Red Hat Single Sign On ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, einen Denial of Service Zustand hervorzurufen, Informationen auszuspähen, Sicherheitsvorkehrungen zu umgehen oder beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1947</guid>
    </item>
  </channel>
</rss>
