<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:57:32 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:6820 — Moderate: prometheus-jmx-exporter security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:6820</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: prometheus-jmx-exporter, AlmaLinux:8: prometheus-jmx-exporter-openjdk11&lt;/p&gt;
&lt;p&gt;Prometheus JMX Exporter is a JMX to Prometheus exporter: a collector that can be configured to scrape and expose MBeans of a JMX target.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: prometheus-jmx-exporter, AlmaLinux:8: prometheus-jmx-exporter-openjdk11&lt;/p&gt;
&lt;p&gt;Prometheus JMX Exporter is a JMX to Prometheus exporter: a collector that can be configured to scrape and expose MBeans of a JMX target.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* snakeyaml: Denial of Service due to missing nested depth limitation for collections (CVE-2022-25857)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:6820</guid>
    </item>
    <item>
      <title>bdu:2023-05621</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05621</link>
      <description>bdu:2023-05621</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05621</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0034 — De multiples vulnérabilités ont été découvertes dans les produits
Oracle. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0034</link>
      <description>certfr-2023-avi-0034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0034</guid>
    </item>
    <item>
      <title>EUVD-2026-173298</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-173298</link>
      <description>EUVD-2026-173298</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-173298</guid>
    </item>
    <item>
      <title>fkie_cve-2022-25857</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-25857</link>
      <description>&lt;p&gt;The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-25857</guid>
    </item>
    <item>
      <title>GHSA-3mc7-4q67-w48m — Uncontrolled Resource Consumption in snakeyaml</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3mc7-4q67-w48m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.yaml:snakeyaml&lt;/p&gt;
&lt;p&gt;The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.yaml:snakeyaml&lt;/p&gt;
&lt;p&gt;The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3mc7-4q67-w48m</guid>
    </item>
    <item>
      <title>gsd-2022-25857</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-25857</link>
      <description>gsd-2022-25857</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-25857</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-25857 — Denial of Service (DoS)</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-25857</link>
      <description>msrc_CVE-2022-25857</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-25857</guid>
    </item>
    <item>
      <title>OESA-2023-1162 — snakeyaml security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1162</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: snakeyaml&lt;/p&gt;
&lt;p&gt;SnakeYAML is a YAML parser and emitter for the Java Virtual Machine. YAML is a data serialization format designed for human readability and interaction with scripting languages.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.(CVE-2022-25857)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38749)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38750)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38751)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.(CVE-2022-38752)&lt;/p&gt;
&lt;p&gt;Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: snakeyaml&lt;/p&gt;
&lt;p&gt;SnakeYAML is a YAML parser and emitter for the Java Virtual Machine. YAML is a data serialization format designed for human readability and interaction with scripting languages.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.(CVE-2022-25857)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38749)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38750)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.(CVE-2022-38751)&#13;
&#13;
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.(CVE-2022-38752)&lt;/p&gt;
&lt;p&gt;Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1162</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12308-1 — snakeyaml-1.31-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12308-1</link>
      <description>&lt;p&gt;snakeyaml-1.31-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;snakeyaml-1.31-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12308-1</guid>
    </item>
    <item>
      <title>RHSA-2022:6757 — Red Hat Security Advisory: Red Hat build of Eclipse Vert.x 4.3.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6757</link>
      <description>&lt;p&gt;snakeyaml: Denial of Service due to missing nested depth limitation for collections graphql-java: DoS by malicious query snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;snakeyaml: Denial of Service due to missing nested depth limitation for collections graphql-java: DoS by malicious query snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6757</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3560-1 — Security update for snakeyaml</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3560-1</link>
      <description>&lt;p&gt;Security update for snakeyaml&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for snakeyaml&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3560-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-25857</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25857</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: snakeyaml, Ubuntu:Pro:16.04:LTS: snakeyaml, Ubuntu:18.04:LTS: snakeyaml, Ubuntu:20.04:LTS: snakeyaml, Ubuntu:22.04:LTS: snakeyaml&lt;/p&gt;
&lt;p&gt;The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: snakeyaml, Ubuntu:Pro:16.04:LTS: snakeyaml, Ubuntu:18.04:LTS: snakeyaml, Ubuntu:20.04:LTS: snakeyaml, Ubuntu:22.04:LTS: snakeyaml&lt;/p&gt;
&lt;p&gt;The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25857</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1635 — Red Hat OpenShift und Red Hat Enterprise Linux: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1635</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift build of Eclipse Vert.x und Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift build of Eclipse Vert.x und Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1635</guid>
    </item>
  </channel>
</rss>
