<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:41:14 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-05216</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05216</link>
      <description>bdu:2023-05216</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05216</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-26291 — CVE-2021-26291 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-26291</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-26291</guid>
    </item>
    <item>
      <title>BIT-maven-2021-26291 — block repositories using http by default</title>
      <link>https://cve.radiocsirt.org/vuln/bit-maven-2021-26291</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: maven&lt;/p&gt;
&lt;p&gt;Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: maven&lt;/p&gt;
&lt;p&gt;Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-maven-2021-26291</guid>
    </item>
    <item>
      <title>certfr-2022-avi-659 — De multiples vulnérabilités ont été découvertes dans Oracle WebLogic.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-659</link>
      <description>certfr-2022-avi-659</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-659</guid>
    </item>
    <item>
      <title>cnvd-2021-36229</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-36229</link>
      <description>cnvd-2021-36229</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-36229</guid>
    </item>
    <item>
      <title>EUVD-2026-24986</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-24986</link>
      <description>EUVD-2026-24986</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-24986</guid>
    </item>
    <item>
      <title>fkie_cve-2021-26291</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-26291</link>
      <description>&lt;p&gt;Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-26291</guid>
    </item>
    <item>
      <title>GHSA-2f88-5hg8-9x2x — Origin Validation Error in Apache Maven</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2f88-5hg8-9x2x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.maven:maven-compat, Maven: org.apache.maven:maven-core&lt;/p&gt;
&lt;p&gt;Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.maven:maven-compat, Maven: org.apache.maven:maven-core&lt;/p&gt;
&lt;p&gt;Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2f88-5hg8-9x2x</guid>
    </item>
    <item>
      <title>gsd-2021-26291</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-26291</link>
      <description>gsd-2021-26291</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-26291</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-26291 — block repositories using http by default</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-26291</link>
      <description>msrc_CVE-2021-26291</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-26291</guid>
    </item>
    <item>
      <title>OESA-2021-1276 — maven security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1276</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: maven, openEuler:20.03-LTS-SP2: maven&lt;/p&gt;
&lt;p&gt;Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project&amp;amp;apos;s build, reporting and documentation from a central piece of information.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html(CVE-2021-26291)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: maven, openEuler:20.03-LTS-SP2: maven&lt;/p&gt;
&lt;p&gt;Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project&amp;amp;apos;s build, reporting and documentation from a central piece of information.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html(CVE-2021-26291)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1276</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10687-1 — clojure-1.10.3.855-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10687-1</link>
      <description>&lt;p&gt;clojure-1.10.3.855-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;clojure-1.10.3.855-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10687-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3880 — Red Hat Security Advisory: Red Hat build of Quarkus 2.2.3 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3880</link>
      <description>&lt;p&gt;jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception wildfly-elytron: possible timing attack in ScramServer resteasy: Error message exposes endpoint class information netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation netty: Request smuggling via content-length header maven: Block repositories using http by default&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception wildfly-elytron: possible timing attack in ScramServer resteasy: Error message exposes endpoint class information netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation netty: Request smuggling via content-length header maven: Block repositories using http by default&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3880</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-26291</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-26291</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: maven, Ubuntu:Pro:16.04:LTS: maven, Ubuntu:Pro:18.04:LTS: maven, Ubuntu:Pro:20.04:LTS: maven, Ubuntu:Pro:22.04:LTS: maven&lt;/p&gt;
&lt;p&gt;Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: maven, Ubuntu:Pro:16.04:LTS: maven, Ubuntu:Pro:18.04:LTS: maven, Ubuntu:Pro:20.04:LTS: maven, Ubuntu:Pro:22.04:LTS: maven&lt;/p&gt;
&lt;p&gt;Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-26291</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1375 — JFrog Artifactory: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</guid>
    </item>
  </channel>
</rss>
