<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:46:09 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-41186</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-41186</link>
      <description>cnvd-2020-41186</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-41186</guid>
    </item>
    <item>
      <title>EUVD-2026-35578</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-35578</link>
      <description>EUVD-2026-35578</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-35578</guid>
    </item>
    <item>
      <title>fkie_cve-2020-1714</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1714</link>
      <description>&lt;p&gt;A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-1714</guid>
    </item>
    <item>
      <title>GHSA-m6mm-q862-j366 — Improper Input Validation in Keycloak</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m6mm-q862-j366</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core, Maven: org.keycloak:keycloak-common&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core, Maven: org.keycloak:keycloak-common&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m6mm-q862-j366</guid>
    </item>
    <item>
      <title>gsd-2020-1714</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-1714</link>
      <description>gsd-2020-1714</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-1714</guid>
    </item>
    <item>
      <title>RHSA-2020:2813 — Red Hat Security Advisory: Red Hat Single Sign-On 7.4.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:2813</link>
      <description>&lt;p&gt;keycloak: verify-token-audience support is missing in the NodeJS adapter keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core undertow: invalid HTTP request with large chunk size keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697) jackson-databind: Serialization gadgets in javax.swing.JEditorPane jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;keycloak: verify-token-audience support is missing in the NodeJS adapter keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core undertow: invalid HTTP request with large chunk size keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697) jackson-databind: Serialization gadgets in javax.swing.JEditorPane jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:2813</guid>
    </item>
  </channel>
</rss>
