<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:52:26 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-344 — Une vulnérabilité a été découverte dans VMware Spring. Elle permet à un
attaquant de provoquer un contournement de la p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-344</link>
      <description>certfr-2022-avi-344</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-344</guid>
    </item>
    <item>
      <title>EUVD-2026-13656</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-13656</link>
      <description>EUVD-2026-13656</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-13656</guid>
    </item>
    <item>
      <title>fkie_cve-2022-22968</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-22968</link>
      <description>&lt;p&gt;In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-22968</guid>
    </item>
    <item>
      <title>GHSA-g5mm-vmx4-3rg7 — Improper handling of case sensitivity in Spring Framework</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g5mm-vmx4-3rg7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-context&lt;/p&gt;
&lt;p&gt;In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. Versions 5.3.19 and 5.2.21 contain a patch for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-context&lt;/p&gt;
&lt;p&gt;In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. Versions 5.3.19 and 5.2.21 contain a patch for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g5mm-vmx4-3rg7</guid>
    </item>
    <item>
      <title>gsd-2022-22968</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-22968</link>
      <description>gsd-2022-22968</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-22968</guid>
    </item>
    <item>
      <title>RHSA-2022:5101 — Red Hat Security Advisory: Red Hat AMQ Broker 7.10.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:5101</link>
      <description>&lt;p&gt;nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties jackson-databind: denial of service via a large depth of nested objects Broker: Malformed message can result in partial DoS (OOM) netty: control chars in header names may lead to HTTP request smuggling amq: AMQ Broker Operator ClusterWide Edit Permissions Due Token Exposure Framework: Data Binding Rules Vulnerability artemis-commons: Apache ActiveMQ Artemis DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties jackson-databind: denial of service via a large depth of nested objects Broker: Malformed message can result in partial DoS (OOM) netty: control chars in header names may lead to HTTP request smuggling amq: AMQ Broker Operator ClusterWide Edit Permissions Due Token Exposure Framework: Data Binding Rules Vulnerability artemis-commons: Apache ActiveMQ Artemis DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:5101</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-22968</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22968</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22968</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0068 — VMware Tanzu Spring Framework: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0068</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Framework ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Framework ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0068</guid>
    </item>
  </channel>
</rss>
