<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:02:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-05588</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-05588</link>
      <description>bdu:2021-05588</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-05588</guid>
    </item>
    <item>
      <title>cnvd-2021-88202</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-88202</link>
      <description>cnvd-2021-88202</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-88202</guid>
    </item>
    <item>
      <title>EUVD-2026-31609</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-31609</link>
      <description>EUVD-2026-31609</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-31609</guid>
    </item>
    <item>
      <title>fkie_cve-2021-41269</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41269</link>
      <description>&lt;p&gt;cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected. The issue was patched and a new version was released. Please upgrade to version 9.1.6. There are no known workarounds known.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected. The issue was patched and a new version was released. Please upgrade to version 9.1.6. There are no known workarounds known.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-41269</guid>
    </item>
    <item>
      <title>GHSA-p9m8-27x8-rg87 — Critical vulnerability found in cron-utils</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p9m8-27x8-rg87</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.cronutils:cron-utils&lt;/p&gt;
&lt;p&gt;### Impact
A Template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected.&lt;/p&gt;
&lt;p&gt;### Patches
The issue was patched and a new version was released. Please upgrade to version 9.1.6.&lt;/p&gt;
&lt;p&gt;### Workarounds
There are no known workarounds up to this moment.&lt;/p&gt;
&lt;p&gt;### References
A description of the issue is provided in [issue 461](https://github.com/jmrozanec/cron-utils/issues/461)&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;Open an issue in the [cron-utils Github repository](https://github.com/jmrozanec/cron-utils)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.cronutils:cron-utils&lt;/p&gt;
&lt;p&gt;### Impact
A Template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected.&lt;/p&gt;
&lt;p&gt;### Patches
The issue was patched and a new version was released. Please upgrade to version 9.1.6.&lt;/p&gt;
&lt;p&gt;### Workarounds
There are no known workarounds up to this moment.&lt;/p&gt;
&lt;p&gt;### References
A description of the issue is provided in [issue 461](https://github.com/jmrozanec/cron-utils/issues/461)&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;Open an issue in the [cron-utils Github repository](https://github.com/jmrozanec/cron-utils)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p9m8-27x8-rg87</guid>
    </item>
    <item>
      <title>gsd-2021-41269</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-41269</link>
      <description>gsd-2021-41269</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-41269</guid>
    </item>
    <item>
      <title>RHSA-2022:0589 — Red Hat Security Advisory: Red Hat build of Quarkus 2.2.5 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0589</link>
      <description>&lt;p&gt;mysql-connector-java: unauthorized access to critical kubernetes-client: Insecure deserialization in unmarshalYaml method jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients cron-utils: template Injection leading to unauthenticated Remote Code Execution&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mysql-connector-java: unauthorized access to critical kubernetes-client: Insecure deserialization in unmarshalYaml method jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients cron-utils: template Injection leading to unauthenticated Remote Code Execution&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0589</guid>
    </item>
  </channel>
</rss>
