<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:06:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-05508</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05508</link>
      <description>bdu:2022-05508</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05508</guid>
    </item>
    <item>
      <title>BIT-jenkins-2021-43859 — Denial of Service by injecting highly recursive collections or maps in XStream</title>
      <link>https://cve.radiocsirt.org/vuln/bit-jenkins-2021-43859</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: jenkins&lt;/p&gt;
&lt;p&gt;XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: jenkins&lt;/p&gt;
&lt;p&gt;XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-jenkins-2021-43859</guid>
    </item>
    <item>
      <title>certfr-2022-avi-597 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
Protect Plus. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-597</link>
      <description>certfr-2022-avi-597</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-597</guid>
    </item>
    <item>
      <title>EUVD-2026-258320</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258320</link>
      <description>EUVD-2026-258320</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258320</guid>
    </item>
    <item>
      <title>fkie_cve-2021-43859</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43859</link>
      <description>&lt;p&gt;XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-43859</guid>
    </item>
    <item>
      <title>GHSA-rmr5-cpv2-vgjf — Denial of Service by injecting highly recursive collections or maps in XStream</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rmr5-cpv2-vgjf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.thoughtworks.xstream:xstream&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream.&lt;/p&gt;
&lt;p&gt;### Patches
XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded.&lt;/p&gt;
&lt;p&gt;### Workarounds
The attack uses the hash code implementation for collections and maps to force an exponential calculation time due to highly recursive structures with in the collection or map. Following types of the Java runtime are affected in Java versions available in December 2021:&lt;/p&gt;
&lt;p&gt;- java.util.HashMap
- java.util.HashSet
- java.util.Hashtable
- java.util.LinkedHashMap
- java.util.LinkedHashSet
- java.util.Stack (older Java revisions only)
- java.util.Vector (older Java revisions only)
- Other third party collection implementations that use their element&amp;#39;s hash code may also be affected&lt;/p&gt;
&lt;p&gt;If your object graph does not use referenced elements at all, you may simply set the NO_REFERENCE mode:
```Java
XStream xstream = new XStream();
xstream.setMode(XStream.NO_REFERENCES);
```&lt;/p&gt;
&lt;p&gt;If your object graph contains neither a Hashtable, HashMap nor a HashSet (or one of the linked variants of it) then you can use the security framework to deny the usage of these types:
```Java
XStream xstream = new XStream();
xstream.denyTypes(new Class[]{
 java.util.HashMap.class, java.util.HashSet.cl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.thoughtworks.xstream:xstream&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream.&lt;/p&gt;
&lt;p&gt;### Patches
XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded.&lt;/p&gt;
&lt;p&gt;### Workarounds
The attack uses the hash code implementation for collections and maps to force an exponential calculation time due to highly recursive structures with in the collection or map. Following types of the Java runtime are affected in Java versions available in December 2021:&lt;/p&gt;
&lt;p&gt;- java.util.HashMap
- java.util.HashSet
- java.util.Hashtable
- java.util.LinkedHashMap
- java.util.LinkedHashSet
- java.util.Stack (older Java revisions only)
- java.util.Vector (older Java revisions only)
- Other third party collection implementations that use their element&amp;#39;s hash code may also be affected&lt;/p&gt;
&lt;p&gt;If your object graph does not use referenced elements at all, you may simply set the NO_REFERENCE mode:
```Java
XStream xstream = new XStream();
xstream.setMode(XStream.NO_REFERENCES);
```&lt;/p&gt;
&lt;p&gt;If your object graph contains neither a Hashtable, HashMap nor a HashSet (or one of the linked variants of it) then you can use the security framework to deny the usage of these types:
```Java
XStream xstream = new XStream();
xstream.denyTypes(new Class[]{
 java.util.HashMap.class, java.util.HashSet.cl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rmr5-cpv2-vgjf</guid>
    </item>
    <item>
      <title>gsd-2021-43859</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-43859</link>
      <description>gsd-2021-43859</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-43859</guid>
    </item>
    <item>
      <title>OESA-2022-1512 — xstream security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1512</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xstream, openEuler:20.03-LTS-SP2: xstream, openEuler:20.03-LTS-SP3: xstream&lt;/p&gt;
&lt;p&gt;Java XML serialization library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.(CVE-2021-43859)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xstream, openEuler:20.03-LTS-SP2: xstream, openEuler:20.03-LTS-SP3: xstream&lt;/p&gt;
&lt;p&gt;Java XML serialization library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.(CVE-2021-43859)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1512</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0817-1 — Security update for xstream</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0817-1</link>
      <description>&lt;p&gt;Security update for xstream&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for xstream&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0817-1</guid>
    </item>
    <item>
      <title>RHSA-2022:1420 — Red Hat Security Advisory: OpenShift Container Platform 3.11.685 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1420</link>
      <description>&lt;p&gt;xstream: Injecting highly recursive collections or maps can cause a DoS workflow-cps: OS command execution through crafted SCM contents workflow-cps-global-lib: OS command execution through crafted SCM contents workflow-multibranch: OS command execution through crafted SCM contents workflow-cps: Pipeline-related plugins follow symbolic links or do not limit path names workflow-cps-global-lib: Pipeline-related plugins follow symbolic links or do not limit path names workflow-cps-global-lib: Pipeline-related plugins follow symbolic links or do not limit path names workflow-multibranch: Pipeline-related plugins follow symbolic links or do not limit path names workflow-cps: Password parameters are included from the original build in replayed builds workflow-cps-global-lib: Sandbox bypass vulnerability workflow-cps-global-lib: Sandbox bypass vulnerability workflow-cps-global-lib: Sandbox bypass vulnerability pipeline-build-step: Password parameter default values exposed&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xstream: Injecting highly recursive collections or maps can cause a DoS workflow-cps: OS command execution through crafted SCM contents workflow-cps-global-lib: OS command execution through crafted SCM contents workflow-multibranch: OS command execution through crafted SCM contents workflow-cps: Pipeline-related plugins follow symbolic links or do not limit path names workflow-cps-global-lib: Pipeline-related plugins follow symbolic links or do not limit path names workflow-cps-global-lib: Pipeline-related plugins follow symbolic links or do not limit path names workflow-multibranch: Pipeline-related plugins follow symbolic links or do not limit path names workflow-cps: Password parameters are included from the original build in replayed builds workflow-cps-global-lib: Sandbox bypass vulnerability workflow-cps-global-lib: Sandbox bypass vulnerability workflow-cps-global-lib: Sandbox bypass vulnerability pipeline-build-step: Password parameter default values exposed&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1420</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0817-1 — Security update for xstream</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0817-1</link>
      <description>&lt;p&gt;Security update for xstream&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for xstream&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0817-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-43859</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43859</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxstream-java, Ubuntu:Pro:16.04:LTS: libxstream-java, Ubuntu:18.04:LTS: libxstream-java, Ubuntu:20.04:LTS: libxstream-java, Ubuntu:22.04:LTS: libxstream-java, Ubuntu:24.04:LTS: libxstream-java, Ubuntu:25.10: libxstream-java, Ubuntu:26.04:LTS: libxstream-java&lt;/p&gt;
&lt;p&gt;XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxstream-java, Ubuntu:Pro:16.04:LTS: libxstream-java, Ubuntu:18.04:LTS: libxstream-java, Ubuntu:20.04:LTS: libxstream-java, Ubuntu:22.04:LTS: libxstream-java, Ubuntu:24.04:LTS: libxstream-java, Ubuntu:25.10: libxstream-java, Ubuntu:26.04:LTS: libxstream-java&lt;/p&gt;
&lt;p&gt;XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43859</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</guid>
    </item>
  </channel>
</rss>
