<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:29:10 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-08651</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08651</link>
      <description>bdu:2023-08651</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08651</guid>
    </item>
    <item>
      <title>certfr-2022-avi-932 — De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft.
Elles permettent à un attaquant de provoquer un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-932</link>
      <description>certfr-2022-avi-932</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-932</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CU18187 — Security fixes in stargate 1.0.90-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cu18187</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Package stargate version 1.0.90-r4 fixes 87 vulnerabilities: ghsa-76h9-2vwh-w278, ghsa-pqr6-cmr2-h8hf, ghsa-fjpj-2g6w-x25r, ghsa-qcwq-55hx-v3vh, ghsa-55g7-9cwv-5qfv...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Package stargate version 1.0.90-r4 fixes 87 vulnerabilities: ghsa-76h9-2vwh-w278, ghsa-pqr6-cmr2-h8hf, ghsa-fjpj-2g6w-x25r, ghsa-qcwq-55hx-v3vh, ghsa-55g7-9cwv-5qfv...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cu18187</guid>
    </item>
    <item>
      <title>EUVD-2026-232740</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232740</link>
      <description>EUVD-2026-232740</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232740</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24823</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24823</link>
      <description>&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one&amp;#39;s own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one&amp;#39;s own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24823</guid>
    </item>
    <item>
      <title>GHSA-269q-hmxg-m83q — Local Information Disclosure Vulnerability in io.netty:netty-codec-http</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-269q-hmxg-m83q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http&lt;/p&gt;
&lt;p&gt;### Description ###
[GHSA-5mcr-gq6c-3hq2](https://github.com/netty/netty/security/advisories/GHSA-5mcr-gq6c-3hq2) (CVE-2021-21290) contains an insufficient fix for the vulnerability identified.&lt;/p&gt;
&lt;p&gt;### Impact ###&lt;/p&gt;
&lt;p&gt;When netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled.&lt;/p&gt;
&lt;p&gt;This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users.&lt;/p&gt;
&lt;p&gt;### Vulnerability Details ###&lt;/p&gt;
&lt;p&gt;To fix the vulnerability the code was changed to the following:&lt;/p&gt;
&lt;p&gt;```java
    @SuppressJava6Requirement(reason = &amp;#34;Guarded by version check&amp;#34;)
    public static File createTempFile(String prefix, String suffix, File directory) throws IOException {
        if (javaVersion() &amp;gt;= 7) {
            if (directory == null) {
                return Files.createTempFile(prefix, suffix).toFile();
            }
            return Files.createTempFile(directory.toPath(), prefix, suffix).toFile();
        }
        if (directory == null) {
            return File.createTempFile(prefix, suffix);
        }
        File file = File.createTempFile(prefix, suffix, directory);
        // Try to adjust the perms, if this fails there is not much else we can do...
        file.setReadable(false, false);
        file.setReadable(true, true…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http&lt;/p&gt;
&lt;p&gt;### Description ###
[GHSA-5mcr-gq6c-3hq2](https://github.com/netty/netty/security/advisories/GHSA-5mcr-gq6c-3hq2) (CVE-2021-21290) contains an insufficient fix for the vulnerability identified.&lt;/p&gt;
&lt;p&gt;### Impact ###&lt;/p&gt;
&lt;p&gt;When netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled.&lt;/p&gt;
&lt;p&gt;This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users.&lt;/p&gt;
&lt;p&gt;### Vulnerability Details ###&lt;/p&gt;
&lt;p&gt;To fix the vulnerability the code was changed to the following:&lt;/p&gt;
&lt;p&gt;```java
    @SuppressJava6Requirement(reason = &amp;#34;Guarded by version check&amp;#34;)
    public static File createTempFile(String prefix, String suffix, File directory) throws IOException {
        if (javaVersion() &amp;gt;= 7) {
            if (directory == null) {
                return Files.createTempFile(prefix, suffix).toFile();
            }
            return Files.createTempFile(directory.toPath(), prefix, suffix).toFile();
        }
        if (directory == null) {
            return File.createTempFile(prefix, suffix);
        }
        File file = File.createTempFile(prefix, suffix, directory);
        // Try to adjust the perms, if this fails there is not much else we can do...
        file.setReadable(false, false);
        file.setReadable(true, true…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-269q-hmxg-m83q</guid>
    </item>
    <item>
      <title>gsd-2022-24823</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24823</link>
      <description>gsd-2022-24823</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24823</guid>
    </item>
    <item>
      <title>OESA-2025-2149 — netty security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2149</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp;amp; clients. %package    help Summary:          Documents for  Buildarch:        noarch Requires:         man info Provides:         -javadoc = - Obsoletes:        -javadoc &amp;amp;amp;lt; - %description help Man pages and other related documents for .&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty&amp;amp;apos;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one&amp;amp;apos;s own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.(CVE-2022-24823)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp;amp; clients. %package    help Summary:          Documents for  Buildarch:        noarch Requires:         man info Provides:         -javadoc = - Obsoletes:        -javadoc &amp;amp;amp;lt; - %description help Man pages and other related documents for .&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty&amp;amp;apos;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one&amp;amp;apos;s own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.(CVE-2022-24823)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2149</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14442-1 — netty-4.1.114-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14442-1</link>
      <description>&lt;p&gt;netty-4.1.114-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-4.1.114-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14442-1</guid>
    </item>
    <item>
      <title>RHSA-2022:5892 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.6 Security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:5892</link>
      <description>&lt;p&gt;minimist: prototype pollution netty: world readable temporary file containing sensitive data com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;minimist: prototype pollution netty: world readable temporary file containing sensitive data com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:5892</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:2096-2 — Security update for netty, netty-tcnative</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:2096-2</link>
      <description>&lt;p&gt;Security update for netty, netty-tcnative&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for netty, netty-tcnative&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:2096-2</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-24823</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24823</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:25.10: netty, Ubuntu:Pro:26.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one&amp;#39;s own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:25.10: netty, Ubuntu:Pro:26.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one&amp;#39;s own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24823</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0508 — IBM Tivoli Netcool/OMNIbus: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0508</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in IBM Tivoli Netcool/OMNIbus ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in IBM Tivoli Netcool/OMNIbus ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0508</guid>
    </item>
  </channel>
</rss>
