<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:07:39 +0000</lastBuildDate>
    <item>
      <title>certfr-2021-avi-417 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-417</link>
      <description>certfr-2021-avi-417</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-417</guid>
    </item>
    <item>
      <title>cnvd-2021-29467</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-29467</link>
      <description>cnvd-2021-29467</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-29467</guid>
    </item>
    <item>
      <title>EUVD-2026-215946</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-215946</link>
      <description>EUVD-2026-215946</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-215946</guid>
    </item>
    <item>
      <title>fkie_cve-2021-22696</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22696</link>
      <description>&lt;p&gt;CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a &amp;#34;request&amp;#34; parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the &amp;#34;request_uri&amp;#34; parameter. CXF was not validating the &amp;#34;request_uri&amp;#34; parameter (apart from ensuring it uses &amp;#34;https) and was making a REST request to the parameter in the request to retrieve a token. This means that CXF was vulnerable to DDos attacks on the authorization server, as specified in section 10.4.1 of the spec. This issue affects Apache CXF versions prior to 3.4.3; Apache CXF versions prior to 3.3.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a &amp;#34;request&amp;#34; parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the &amp;#34;request_uri&amp;#34; parameter. CXF was not validating the &amp;#34;request_uri&amp;#34; parameter (apart from ensuring it uses &amp;#34;https) and was making a REST request to the parameter in the request to retrieve a token. This means that CXF was vulnerable to DDos attacks on the authorization server, as specified in section 10.4.1 of the spec. This issue affects Apache CXF versions prior to 3.4.3; Apache CXF versions prior to 3.3.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-22696</guid>
    </item>
    <item>
      <title>GHSA-7q4h-pj78-j7vg — Authorization service vulnerable to DDos attacks in Apache CFX</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7q4h-pj78-j7vg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf, Maven: org.apache.cxf:apache-cxf&lt;/p&gt;
&lt;p&gt;CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a &amp;#34;request&amp;#34; parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the &amp;#34;request_uri&amp;#34; parameter. CXF was not validating the &amp;#34;request_uri&amp;#34; parameter (apart from ensuring it uses &amp;#34;https) and was making a REST request to the parameter in the request to retrieve a token. This means that CXF was vulnerable to DDos attacks on the authorization server, as specified in section 10.4.1 of the spec. This issue affects Apache CXF versions prior to 3.4.3; Apache CXF versions prior to 3.3.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf, Maven: org.apache.cxf:apache-cxf&lt;/p&gt;
&lt;p&gt;CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a &amp;#34;request&amp;#34; parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the &amp;#34;request_uri&amp;#34; parameter. CXF was not validating the &amp;#34;request_uri&amp;#34; parameter (apart from ensuring it uses &amp;#34;https) and was making a REST request to the parameter in the request to retrieve a token. This means that CXF was vulnerable to DDos attacks on the authorization server, as specified in section 10.4.1 of the spec. This issue affects Apache CXF versions prior to 3.4.3; Apache CXF versions prior to 3.3.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7q4h-pj78-j7vg</guid>
    </item>
    <item>
      <title>gsd-2021-22696</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-22696</link>
      <description>gsd-2021-22696</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-22696</guid>
    </item>
    <item>
      <title>RHSA-2021:5134 — Red Hat Security Advisory: Red Hat Fuse 7.10.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:5134</link>
      <description>&lt;p&gt;nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem mysql-connector-java: allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors which could result in unauthorized update, insert or delete mysql-connector-java: allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors which could result in unauthorized update, insert or delete log4j: improper validation of certificate with host mismatch in SMTP appender batik: SSRF due to improper input validation by the NodePickerPanel xmlgraphics-commons: SSRF due to improper input validation by the XMPParser tomcat: Apache Tomcat HTTP/2 Request mix-up libthrift: potential DoS when processing untrusted payloads bouncycastle: Timing issue within the EC math library groovy: OS temporary directory leads to information disclosure tomcat: HTTP/2 request header mix-up XStream: remote code execution due to insecure XML deserialization when relying on blocklists XStream: arbitrary file deletion on the local host when unmarshalling jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS undertow: special character in query results in server errors jackson-dataformat-cbor: Unchecked allocation…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem mysql-connector-java: allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors which could result in unauthorized update, insert or delete mysql-connector-java: allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors which could result in unauthorized update, insert or delete log4j: improper validation of certificate with host mismatch in SMTP appender batik: SSRF due to improper input validation by the NodePickerPanel xmlgraphics-commons: SSRF due to improper input validation by the XMPParser tomcat: Apache Tomcat HTTP/2 Request mix-up libthrift: potential DoS when processing untrusted payloads bouncycastle: Timing issue within the EC math library groovy: OS temporary directory leads to information disclosure tomcat: HTTP/2 request header mix-up XStream: remote code execution due to insecure XML deserialization when relying on blocklists XStream: arbitrary file deletion on the local host when unmarshalling jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS undertow: special character in query results in server errors jackson-dataformat-cbor: Unchecked allocation…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:5134</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0227 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</guid>
    </item>
  </channel>
</rss>
