<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:20:47 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-03434</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-03434</link>
      <description>bdu:2022-03434</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-03434</guid>
    </item>
    <item>
      <title>BIT-tomcat-2022-29885 — EncryptInterceptor does not provide complete protection on insecure networks</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2022-29885</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;The documentation of Apache Tomcat 10.1.0 to 10.1.0, 10.0.0 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;The documentation of Apache Tomcat 10.1.0 to 10.1.0, 10.0.0 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2022-29885</guid>
    </item>
    <item>
      <title>certfr-2022-avi-443 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un
attaquant de provoquer un déni de service à dis…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-443</link>
      <description>certfr-2022-avi-443</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-443</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AJ47488 — When using the RemoteIpFilter with requests received from a    reverse proxy via HTTP that include the X-Forwarded-Prot…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aj47488</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tomcat10&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the tomcat10 package. When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tomcat10&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the tomcat10 package. When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aj47488</guid>
    </item>
    <item>
      <title>cnvd-2022-49970</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-49970</link>
      <description>cnvd-2022-49970</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-49970</guid>
    </item>
    <item>
      <title>EUVD-2026-16308</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-16308</link>
      <description>EUVD-2026-16308</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-16308</guid>
    </item>
    <item>
      <title>fkie_cve-2022-29885</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-29885</link>
      <description>&lt;p&gt;The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-29885</guid>
    </item>
    <item>
      <title>GHSA-r84p-88g2-2vx2 — Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r84p-88g2-2vx2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r84p-88g2-2vx2</guid>
    </item>
    <item>
      <title>gsd-2022-29885</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-29885</link>
      <description>gsd-2022-29885</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-29885</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-29885</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-29885</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-29885</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0467 — Apache Tomcat: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0467</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0467</guid>
    </item>
  </channel>
</rss>
