<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:31:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-04263</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-04263</link>
      <description>bdu:2025-04263</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-04263</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>EUVD-2026-46248</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-46248</link>
      <description>EUVD-2026-46248</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-46248</guid>
    </item>
    <item>
      <title>fkie_cve-2020-26945</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-26945</link>
      <description>&lt;p&gt;MyBatis before 3.5.6 mishandles deserialization of object streams.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MyBatis before 3.5.6 mishandles deserialization of object streams.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-26945</guid>
    </item>
    <item>
      <title>GHSA-qq48-m4jx-xqh8 — "Deserialization errors in MyBatis"</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qq48-m4jx-xqh8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.mybatis:mybatis&lt;/p&gt;
&lt;p&gt;MyBatis before 3.5.6 mishandles deserialization of object streams leading to potential cache poisoning.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.mybatis:mybatis&lt;/p&gt;
&lt;p&gt;MyBatis before 3.5.6 mishandles deserialization of object streams leading to potential cache poisoning.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qq48-m4jx-xqh8</guid>
    </item>
    <item>
      <title>gsd-2020-26945</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-26945</link>
      <description>gsd-2020-26945</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-26945</guid>
    </item>
    <item>
      <title>OESA-2021-1292 — mybatis security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1292</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP2: mybatis&lt;/p&gt;
&lt;p&gt;The MyBatis data mapper framework makes it easier to use a relational database with object-oriented applications. MyBatis couples objects with stored procedures or SQL statements using a XML descriptor or annotations. Simplicity is the biggest advantage of the MyBatis data mapper over object relational mapping tools. To use the MyBatis data mapper, you rely on your own objects, XML, and SQL. There is little to learn that you don&amp;amp;apos;t already know. With the MyBatis data mapper, you have the full power of both SQL and stored procedures at your fingertips. The MyBatis project is developed and maintained by a team that includes the original creators of the &amp;amp;quot;iBATIS&amp;amp;quot; data mapper. The Apache project was retired and continued here.&#13;
&#13;
Security Fix(es):&#13;
&#13;
MyBatis before 3.5.6 mishandles deserialization of object streams.(CVE-2020-26945)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP2: mybatis&lt;/p&gt;
&lt;p&gt;The MyBatis data mapper framework makes it easier to use a relational database with object-oriented applications. MyBatis couples objects with stored procedures or SQL statements using a XML descriptor or annotations. Simplicity is the biggest advantage of the MyBatis data mapper over object relational mapping tools. To use the MyBatis data mapper, you rely on your own objects, XML, and SQL. There is little to learn that you don&amp;amp;apos;t already know. With the MyBatis data mapper, you have the full power of both SQL and stored procedures at your fingertips. The MyBatis project is developed and maintained by a team that includes the original creators of the &amp;amp;quot;iBATIS&amp;amp;quot; data mapper. The Apache project was retired and continued here.&#13;
&#13;
Security Fix(es):&#13;
&#13;
MyBatis before 3.5.6 mishandles deserialization of object streams.(CVE-2020-26945)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1292</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11070-1 — mybatis-3.5.6-1.6 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11070-1</link>
      <description>&lt;p&gt;mybatis-3.5.6-1.6 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mybatis-3.5.6-1.6 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11070-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3140 — Red Hat Security Advisory: Red Hat Fuse 7.9.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3140</link>
      <description>&lt;p&gt;log4j: Socket receiver deserialization vulnerability snakeyaml: Billion laughs attack via alias feature apache-commons-compress: Infinite loop in name encoding algorithm wildfly: The &amp;#39;enabled-protocols&amp;#39; value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class olingo-odata: Server side request forgery in AsyncResponseWrapperImpl tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability spring-cloud-config-server: sending a request using a specially crafted URL can lead to a directory traversal attack springframework: RFD protection bypass via jsessionid Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 tomcat: deserialization flaw in session persistence storage leading to RCE RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack hibernate-validator: Improper input validation in the interpolation of constraint error messages wildfly-elytron: session fixation when using FORM authentication undertow: invalid HTTP request with large chunk size tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;log4j: Socket receiver deserialization vulnerability snakeyaml: Billion laughs attack via alias feature apache-commons-compress: Infinite loop in name encoding algorithm wildfly: The &amp;#39;enabled-protocols&amp;#39; value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class olingo-odata: Server side request forgery in AsyncResponseWrapperImpl tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability spring-cloud-config-server: sending a request using a specially crafted URL can lead to a directory traversal attack springframework: RFD protection bypass via jsessionid Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 tomcat: deserialization flaw in session persistence storage leading to RCE RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack hibernate-validator: Improper input validation in the interpolation of constraint error messages wildfly-elytron: session fixation when using FORM authentication undertow: invalid HTTP request with large chunk size tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3140</guid>
    </item>
  </channel>
</rss>
