<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:33:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-35556</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-35556</link>
      <description>EUVD-2026-35556</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-35556</guid>
    </item>
    <item>
      <title>fkie_cve-2020-1729</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1729</link>
      <description>&lt;p&gt;A flaw was found in SmallRye&amp;#39;s API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in SmallRye&amp;#39;s API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-1729</guid>
    </item>
    <item>
      <title>GHSA-54fx-gm74-q676 — Permissions bypass in SmallRye</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-54fx-gm74-q676</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.smallrye.config:smallrye-config&lt;/p&gt;
&lt;p&gt;A flaw was found in SmallRye&amp;#39;s API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.smallrye.config:smallrye-config&lt;/p&gt;
&lt;p&gt;A flaw was found in SmallRye&amp;#39;s API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-54fx-gm74-q676</guid>
    </item>
    <item>
      <title>gsd-2020-1729</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-1729</link>
      <description>gsd-2020-1729</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-1729</guid>
    </item>
    <item>
      <title>RHSA-2020:2058 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.8 on RHEL 6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:2058</link>
      <description>&lt;p&gt;jackson-mapper-asl: XML external entity similar to CVE-2016-3720 cxf: OpenId Connect token service does not properly validate the clientId cxf: reflected XSS in the services listing page Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader Soteria: security identity corruption across concurrent threads undertow: AJP File Read/Inclusion Vulnerability undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass cryptacular: excessive memory allocation during a decode operation undertow: Memory exhaustion issue in HttpReadListener via &amp;#34;Expect: 100-continue&amp;#34; header undertow: invalid HTTP request with large chunk size&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-mapper-asl: XML external entity similar to CVE-2016-3720 cxf: OpenId Connect token service does not properly validate the clientId cxf: reflected XSS in the services listing page Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader Soteria: security identity corruption across concurrent threads undertow: AJP File Read/Inclusion Vulnerability undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass cryptacular: excessive memory allocation during a decode operation undertow: Memory exhaustion issue in HttpReadListener via &amp;#34;Expect: 100-continue&amp;#34; header undertow: invalid HTTP request with large chunk size&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:2058</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2123 — Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2123</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Angriff durchzuführen, einen Denial of Service Zustand herbeizuführen, Informationen offenzulegen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Angriff durchzuführen, einen Denial of Service Zustand herbeizuführen, Informationen offenzulegen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2123</guid>
    </item>
  </channel>
</rss>
