<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:22:09 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1860 — Moderate: maven:3.6 security and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1860</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aopalliance, AlmaLinux:8: apache-commons-cli, AlmaLinux:8: apache-commons-codec, AlmaLinux:8: apache-commons-io, AlmaLinux:8: apache-commons-lang3, AlmaLinux:8: atinject, AlmaLinux:8: cdi-api, AlmaLinux:8: geronimo-annotation, AlmaLinux:8: google-guice, AlmaLinux:8: guava and 22 more&lt;/p&gt;
&lt;p&gt;Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project&amp;#39;s build, reporting and documentation from a central piece of information.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* apache-httpclient: incorrect handling of malformed authority component in request URIs (CVE-2020-13956)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aopalliance, AlmaLinux:8: apache-commons-cli, AlmaLinux:8: apache-commons-codec, AlmaLinux:8: apache-commons-io, AlmaLinux:8: apache-commons-lang3, AlmaLinux:8: atinject, AlmaLinux:8: cdi-api, AlmaLinux:8: geronimo-annotation, AlmaLinux:8: google-guice, AlmaLinux:8: guava and 22 more&lt;/p&gt;
&lt;p&gt;Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project&amp;#39;s build, reporting and documentation from a central piece of information.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* apache-httpclient: incorrect handling of malformed authority component in request URIs (CVE-2020-13956)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1860</guid>
    </item>
    <item>
      <title>bdu:2023-05212</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05212</link>
      <description>bdu:2023-05212</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05212</guid>
    </item>
    <item>
      <title>certfr-2021-avi-556 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-556</link>
      <description>certfr-2021-avi-556</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-556</guid>
    </item>
    <item>
      <title>cnvd-2021-24248</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-24248</link>
      <description>cnvd-2021-24248</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-24248</guid>
    </item>
    <item>
      <title>EUVD-2026-262110</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262110</link>
      <description>EUVD-2026-262110</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262110</guid>
    </item>
    <item>
      <title>fkie_cve-2020-13956</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13956</link>
      <description>&lt;p&gt;Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-13956</guid>
    </item>
    <item>
      <title>GHSA-7r82-7xv7-xcpj — Cross-site scripting in Apache HttpClient</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7r82-7xv7-xcpj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.httpcomponents:httpclient&lt;/p&gt;
&lt;p&gt;Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.httpcomponents:httpclient&lt;/p&gt;
&lt;p&gt;Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7r82-7xv7-xcpj</guid>
    </item>
    <item>
      <title>gsd-2020-13956</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-13956</link>
      <description>gsd-2020-13956</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-13956</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10687-1 — clojure-1.10.3.855-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10687-1</link>
      <description>&lt;p&gt;clojure-1.10.3.855-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;clojure-1.10.3.855-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10687-1</guid>
    </item>
    <item>
      <title>RHSA-2021:0084 — Red Hat Security Advisory: Red Hat build of Quarkus 1.7.6 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0084</link>
      <description>&lt;p&gt;apache-httpclient: incorrect handling of malformed authority component in request URIs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache-httpclient: incorrect handling of malformed authority component in request URIs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0084</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:4036-1 — Security update for httpcomponents-client, httpcomponents-core</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:4036-1</link>
      <description>&lt;p&gt;Security update for httpcomponents-client, httpcomponents-core&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for httpcomponents-client, httpcomponents-core&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:4036-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-13956</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13956</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: httpcomponents-client, Ubuntu:Pro:16.04:LTS: httpcomponents-client, Ubuntu:Pro:18.04:LTS: httpcomponents-client, Ubuntu:Pro:20.04:LTS: httpcomponents-client&lt;/p&gt;
&lt;p&gt;Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: httpcomponents-client, Ubuntu:Pro:16.04:LTS: httpcomponents-client, Ubuntu:Pro:18.04:LTS: httpcomponents-client, Ubuntu:Pro:20.04:LTS: httpcomponents-client&lt;/p&gt;
&lt;p&gt;Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13956</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0044 — Apache HttpComponents: Schwachstelle ermöglicht Täuschung des Nutzers</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0044</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache HttpComponents ausnutzen, um den Nutzer zu täuschen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache HttpComponents ausnutzen, um den Nutzer zu täuschen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0044</guid>
    </item>
  </channel>
</rss>
