<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:43:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-01808</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01808</link>
      <description>bdu:2021-01808</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01808</guid>
    </item>
    <item>
      <title>BIT-tomcat-2021-25329 — Incomplete fix for CVE-2020-9484</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2021-25329</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0 to 10.0.0, 9.0.0 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0 to 10.0.0, 9.0.0 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2021-25329</guid>
    </item>
    <item>
      <title>certfr-2021-avi-164 — De multiples vulnérabilités ont été découvertes dans Apache Tomcat.
Elles permettent à un attaquant de provoquer une ex…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-164</link>
      <description>certfr-2021-avi-164</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-164</guid>
    </item>
    <item>
      <title>EUVD-2026-215951</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-215951</link>
      <description>EUVD-2026-215951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-215951</guid>
    </item>
    <item>
      <title>fkie_cve-2021-25329</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-25329</link>
      <description>&lt;p&gt;The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-25329</guid>
    </item>
    <item>
      <title>GHSA-jgwr-3qm3-26f3 — Potential remote code execution in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jgwr-3qm3-26f3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jgwr-3qm3-26f3</guid>
    </item>
    <item>
      <title>gsd-2021-25329</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-25329</link>
      <description>gsd-2021-25329</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-25329</guid>
    </item>
    <item>
      <title>OESA-2021-1117 — tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1117</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: tomcat&lt;/p&gt;
&lt;p&gt;The Apache Tomcat software is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. We invite you to participate in this open development project&#13;
&#13;
Security Fix(es):&#13;
&#13;
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.(CVE-2021-25329)&#13;
&#13;
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A&amp;amp;apos;s request.(CVE-2021-25122)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: tomcat&lt;/p&gt;
&lt;p&gt;The Apache Tomcat software is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. We invite you to participate in this open development project&#13;
&#13;
Security Fix(es):&#13;
&#13;
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.(CVE-2021-25329)&#13;
&#13;
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A&amp;amp;apos;s request.(CVE-2021-25122)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1117</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0496-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0496-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0496-1</guid>
    </item>
    <item>
      <title>RHSA-2021:2561 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.5.0 Security release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:2561</link>
      <description>&lt;p&gt;hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used tomcat: Request mix-up with h2c tomcat: Incomplete fix for CVE-2020-9484 (RCE via session persistence)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used tomcat: Request mix-up with h2c tomcat: Incomplete fix for CVE-2020-9484 (RCE via session persistence)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:2561</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:0988-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:0988-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:0988-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-25329</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-25329</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:Pro:14.04:LTS: tomcat6, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:20.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:Pro:14.04:LTS: tomcat6, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:20.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-25329</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</guid>
    </item>
  </channel>
</rss>
