<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:59:29 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03157</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03157</link>
      <description>bdu:2021-03157</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03157</guid>
    </item>
    <item>
      <title>certfr-2021-avi-407 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-407</link>
      <description>certfr-2021-avi-407</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-407</guid>
    </item>
    <item>
      <title>EUVD-2026-210658</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-210658</link>
      <description>EUVD-2026-210658</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-210658</guid>
    </item>
    <item>
      <title>fkie_cve-2020-26258</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-26258</link>
      <description>&lt;p&gt;XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. If you rely on XStream&amp;#39;s default blacklist of the Security Framework, you will have to use at least version 1.4.15. The reported vulnerability does not exist if running Java 15 or higher. No user is affected who followed the recommendation to setup XStream&amp;#39;s Security Framework with a whitelist! Anyone relying on XStream&amp;#39;s default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability. Users of XStream 1.4.14 or below who still want to use XStream default blacklist can use a workaround described in more detailed in the referenced advisories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. If you rely on XStream&amp;#39;s default blacklist of the Security Framework, you will have to use at least version 1.4.15. The reported vulnerability does not exist if running Java 15 or higher. No user is affected who followed the recommendation to setup XStream&amp;#39;s Security Framework with a whitelist! Anyone relying on XStream&amp;#39;s default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability. Users of XStream 1.4.14 or below who still want to use XStream default blacklist can use a workaround described in more detailed in the referenced advisories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-26258</guid>
    </item>
    <item>
      <title>GHSA-4cch-wxpw-8p28 — Server-Side Forgery Request can be activated unmarshalling with XStream</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4cch-wxpw-8p28</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.thoughtworks.xstream:xstream&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream.&lt;/p&gt;
&lt;p&gt;### Patches
If you rely on XStream&amp;#39;s default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.15.&lt;/p&gt;
&lt;p&gt;### Workarounds
The reported vulnerability does not exist running Java 15 or higher.&lt;/p&gt;
&lt;p&gt;No user is affected, who followed the recommendation to setup XStream&amp;#39;s Security Framework with a whitelist! Anyone relying on XStream&amp;#39;s default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability.&lt;/p&gt;
&lt;p&gt;Users of XStream 1.4.14 or below who still insist to use XStream default blacklist - despite that clear recommendation - can use a workaround depending on their version in use.&lt;/p&gt;
&lt;p&gt;Users of XStream 1.4.14 can simply add two lines to XStream&amp;#39;s setup code:
```Java
xstream.denyTypes(new String[]{ &amp;#34;jdk.nashorn.internal.objects.NativeString&amp;#34; });
xstream.denyTypesByRegExp(new String[]{ &amp;#34;.*\\.ReadAllStream\\$FileStream&amp;#34; });
```&lt;/p&gt;
&lt;p&gt;Users of XStream 1.4.14 to 1.4.13 can simply add three lines to XStream&amp;#39;s setup code:
```Java
xstream.denyTypes(new String[]{ &amp;#34;javax.imageio.ImageIO$ContainsFilter&amp;#34;, &amp;#34;jdk.nashorn.internal.objects.NativeString&amp;#34; });
xstream.denyTypes(new Class[]{ java.lang.ProcessBuilder.class });
xstream.denyTypesByRegExp(new String[]{ &amp;#34;.*\\.ReadAllStream\\$FileStream&amp;#34; });
```
Users of XStream 1.4.1…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.thoughtworks.xstream:xstream&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream.&lt;/p&gt;
&lt;p&gt;### Patches
If you rely on XStream&amp;#39;s default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.15.&lt;/p&gt;
&lt;p&gt;### Workarounds
The reported vulnerability does not exist running Java 15 or higher.&lt;/p&gt;
&lt;p&gt;No user is affected, who followed the recommendation to setup XStream&amp;#39;s Security Framework with a whitelist! Anyone relying on XStream&amp;#39;s default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability.&lt;/p&gt;
&lt;p&gt;Users of XStream 1.4.14 or below who still insist to use XStream default blacklist - despite that clear recommendation - can use a workaround depending on their version in use.&lt;/p&gt;
&lt;p&gt;Users of XStream 1.4.14 can simply add two lines to XStream&amp;#39;s setup code:
```Java
xstream.denyTypes(new String[]{ &amp;#34;jdk.nashorn.internal.objects.NativeString&amp;#34; });
xstream.denyTypesByRegExp(new String[]{ &amp;#34;.*\\.ReadAllStream\\$FileStream&amp;#34; });
```&lt;/p&gt;
&lt;p&gt;Users of XStream 1.4.14 to 1.4.13 can simply add three lines to XStream&amp;#39;s setup code:
```Java
xstream.denyTypes(new String[]{ &amp;#34;javax.imageio.ImageIO$ContainsFilter&amp;#34;, &amp;#34;jdk.nashorn.internal.objects.NativeString&amp;#34; });
xstream.denyTypes(new Class[]{ java.lang.ProcessBuilder.class });
xstream.denyTypesByRegExp(new String[]{ &amp;#34;.*\\.ReadAllStream\\$FileStream&amp;#34; });
```
Users of XStream 1.4.1…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4cch-wxpw-8p28</guid>
    </item>
    <item>
      <title>gsd-2020-26258</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-26258</link>
      <description>gsd-2020-26258</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-26258</guid>
    </item>
    <item>
      <title>OESA-2021-1015 — xstream security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1015</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xstream&lt;/p&gt;
&lt;p&gt;XStream is a simple library to serialize objects to XML and back again. A high level facade is supplied that simplifies common use cases. Custom objects can be serialized without need for specifying mappings. Speed and low memory footprint are a crucial part of the design, making it suitable for large object graphs or systems with high message throughput. No information is duplicated that can be obtained via reflection. This results in XML that is easier to read for humans and more compact than native Java serialization. XStream serializes internal fields, including private and final. Supports non-public and inner classes. Classes are not required to have default constructor. Duplicate references encountered in the object-model will be maintained. Supports circular references. By implementing an interface, XStream can serialize directly to/from any tree structure (not just XML). Strategies can be registered allowing customization of how particular types are represented as XML. When an exception occurs due to malformed XML, detailed diagnostics are provided to help isolate and fix the problem.\r\n\r\n&#13;
Security Fix(es):\r\n\r\n&#13;
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. I…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xstream&lt;/p&gt;
&lt;p&gt;XStream is a simple library to serialize objects to XML and back again. A high level facade is supplied that simplifies common use cases. Custom objects can be serialized without need for specifying mappings. Speed and low memory footprint are a crucial part of the design, making it suitable for large object graphs or systems with high message throughput. No information is duplicated that can be obtained via reflection. This results in XML that is easier to read for humans and more compact than native Java serialization. XStream serializes internal fields, including private and final. Supports non-public and inner classes. Classes are not required to have default constructor. Duplicate references encountered in the object-model will be maintained. Supports circular references. By implementing an interface, XStream can serialize directly to/from any tree structure (not just XML). Strategies can be registered allowing customization of how particular types are represented as XML. When an exception occurs due to malformed XML, detailed diagnostics are provided to help isolate and fix the problem.\r\n\r\n&#13;
Security Fix(es):\r\n\r\n&#13;
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. I…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1015</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0140-1 — Security update for xstream</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0140-1</link>
      <description>&lt;p&gt;Security update for xstream&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for xstream&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0140-1</guid>
    </item>
    <item>
      <title>RHSA-2021:2139 — Red Hat Security Advisory: Red Hat Data Grid 8.2.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:2139</link>
      <description>&lt;p&gt;infinispan-server-rest: Actions with effects should not be permitted via GET requests using REST API XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling XStream: arbitrary file deletion on the local host when unmarshalling netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation XStream: allow a remote attacker to cause DoS only by manipulating the processed input stream XStream: SSRF via crafted input stream XStream: arbitrary file deletion on the local host via crafted input stream XStream: Unsafe deserizaliation of javax.sql.rowset.BaseRowSet XStream: Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry XStream: Unsafe deserizaliation of sun.swing.SwingLazyValue XStream: Unsafe deserizaliation of com.sun.tools.javac.processing.JavacProcessingEnvironment NameProcessIterator XStream: ReDoS vulnerability XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host XStream: Unsafe deserizaliation of com.sun.org.apache.bcel.internal.util.ClassLoader XStream: allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream netty: Request smuggling via content-length header Infinispan: Authentication bypass on REST endpoints when using DIGEST authentication mechanism&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;infinispan-server-rest: Actions with effects should not be permitted via GET requests using REST API XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling XStream: arbitrary file deletion on the local host when unmarshalling netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation XStream: allow a remote attacker to cause DoS only by manipulating the processed input stream XStream: SSRF via crafted input stream XStream: arbitrary file deletion on the local host via crafted input stream XStream: Unsafe deserizaliation of javax.sql.rowset.BaseRowSet XStream: Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry XStream: Unsafe deserizaliation of sun.swing.SwingLazyValue XStream: Unsafe deserizaliation of com.sun.tools.javac.processing.JavacProcessingEnvironment NameProcessIterator XStream: ReDoS vulnerability XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host XStream: Unsafe deserizaliation of com.sun.org.apache.bcel.internal.util.ClassLoader XStream: allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream netty: Request smuggling via content-length header Infinispan: Authentication bypass on REST endpoints when using DIGEST authentication mechanism&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:2139</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:0176-1 — Security update for xstream</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:0176-1</link>
      <description>&lt;p&gt;Security update for xstream&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for xstream&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:0176-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-26258</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-26258</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxstream-java, Ubuntu:Pro:16.04:LTS: libxstream-java, Ubuntu:18.04:LTS: libxstream-java, Ubuntu:20.04:LTS: libxstream-java&lt;/p&gt;
&lt;p&gt;XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. If you rely on XStream&amp;#39;s default blacklist of the Security Framework, you will have to use at least version 1.4.15. The reported vulnerability does not exist if running Java 15 or higher. No user is affected who followed the recommendation to setup XStream&amp;#39;s Security Framework with a whitelist! Anyone relying on XStream&amp;#39;s default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability. Users of XStream 1.4.14 or below who still want to use XStream default blacklist can use a workaround described in more detailed in the referenced advisories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxstream-java, Ubuntu:Pro:16.04:LTS: libxstream-java, Ubuntu:18.04:LTS: libxstream-java, Ubuntu:20.04:LTS: libxstream-java&lt;/p&gt;
&lt;p&gt;XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. If you rely on XStream&amp;#39;s default blacklist of the Security Framework, you will have to use at least version 1.4.15. The reported vulnerability does not exist if running Java 15 or higher. No user is affected who followed the recommendation to setup XStream&amp;#39;s Security Framework with a whitelist! Anyone relying on XStream&amp;#39;s default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability. Users of XStream 1.4.14 or below who still want to use XStream default blacklist can use a workaround described in more detailed in the referenced advisories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-26258</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0180 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</guid>
    </item>
  </channel>
</rss>
