<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:53:19 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-00169</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-00169</link>
      <description>bdu:2023-00169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-00169</guid>
    </item>
    <item>
      <title>EUVD-2026-241327</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-241327</link>
      <description>EUVD-2026-241327</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-241327</guid>
    </item>
    <item>
      <title>fkie_cve-2022-36944</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36944</link>
      <description>&lt;p&gt;Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-36944</guid>
    </item>
    <item>
      <title>GHSA-8qv5-68g4-248j — Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserialization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8qv5-68g4-248j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.scala-lang:scala-library&lt;/p&gt;
&lt;p&gt;Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with LazyList object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.scala-lang:scala-library&lt;/p&gt;
&lt;p&gt;Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with LazyList object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8qv5-68g4-248j</guid>
    </item>
    <item>
      <title>gsd-2022-36944</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-36944</link>
      <description>gsd-2022-36944</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-36944</guid>
    </item>
    <item>
      <title>RHSA-2023:3223 — Red Hat Security Advisory: Red Hat AMQ Streams 2.4.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:3223</link>
      <description>&lt;p&gt;jackson-databind: denial of service via a large depth of nested objects okhttp: information disclosure via improperly used cryptographic function netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode netty: world readable temporary file containing sensitive data scala: deserialization gadget chain jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or JSON data jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS jackson-databind: use of deeply nested arrays Streams: component version with information disclosure flaw json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) kafka: RCE/DoS via SASL JAAS JndiLoginModule configuration in Kafka Connect&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind: denial of service via a large depth of nested objects okhttp: information disclosure via improperly used cryptographic function netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode netty: world readable temporary file containing sensitive data scala: deserialization gadget chain jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or JSON data jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS jackson-databind: use of deeply nested arrays Streams: component version with information disclosure flaw json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) kafka: RCE/DoS via SASL JAAS JndiLoginModule configuration in Kafka Connect&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:3223</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2022-36944</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36944</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: scala, Ubuntu:Pro:18.04:LTS: scala, Ubuntu:Pro:20.04:LTS: scala, Ubuntu:22.04:LTS: scala, Ubuntu:24.04:LTS: scala, Ubuntu:25.04: scala&lt;/p&gt;
&lt;p&gt;Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: scala, Ubuntu:Pro:18.04:LTS: scala, Ubuntu:Pro:20.04:LTS: scala, Ubuntu:22.04:LTS: scala, Ubuntu:24.04:LTS: scala, Ubuntu:25.04: scala&lt;/p&gt;
&lt;p&gt;Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36944</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2345 — Camunda: Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2345</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Camunda ausnutzen, um seine Privilegien zu erhöhen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Camunda ausnutzen, um seine Privilegien zu erhöhen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2345</guid>
    </item>
  </channel>
</rss>
