<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:56:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-08465</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08465</link>
      <description>bdu:2023-08465</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08465</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0276 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à un attaquant d…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276</link>
      <description>certfr-2023-avi-0276</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-MG63413 — Security fixes in spark-sc213-jdk17-py312 3.5.8-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-mg63413</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: spark-sc213-jdk17-py312&lt;/p&gt;
&lt;p&gt;Package spark-sc213-jdk17-py312 version 3.5.8-r0 fixes 74 vulnerabilities: CVE-2026-54515, ghsa-5jmj-h7xm-6q6v, ghsa-337m-mw94-2v6g, CVE-2026-45205, ghsa-2r2c-cx56-8933...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: spark-sc213-jdk17-py312&lt;/p&gt;
&lt;p&gt;Package spark-sc213-jdk17-py312 version 3.5.8-r0 fixes 74 vulnerabilities: CVE-2026-54515, ghsa-5jmj-h7xm-6q6v, ghsa-337m-mw94-2v6g, CVE-2026-45205, ghsa-2r2c-cx56-8933...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-mg63413</guid>
    </item>
    <item>
      <title>EUVD-2026-232058</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232058</link>
      <description>EUVD-2026-232058</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232058</guid>
    </item>
    <item>
      <title>fkie_cve-2022-40152</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-40152</link>
      <description>&lt;p&gt;Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-40152</guid>
    </item>
    <item>
      <title>GHSA-3f7h-mf4q-vrm4 — Denial of Service due to parser crash</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3f7h-mf4q-vrm4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.woodstox:woodstox-core&lt;/p&gt;
&lt;p&gt;Those using FasterXML/woodstox to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.&lt;/p&gt;
&lt;p&gt;This vulnerability is only relevant for users making use of the DTD parsing functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.woodstox:woodstox-core&lt;/p&gt;
&lt;p&gt;Those using FasterXML/woodstox to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.&lt;/p&gt;
&lt;p&gt;This vulnerability is only relevant for users making use of the DTD parsing functionality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3f7h-mf4q-vrm4</guid>
    </item>
    <item>
      <title>gsd-2022-40152</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-40152</link>
      <description>gsd-2022-40152</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-40152</guid>
    </item>
    <item>
      <title>OESA-2024-2378 — woodstox-core security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2378</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: woodstox-core, openEuler:24.03-LTS: woodstox-core, openEuler:22.03-LTS-SP4: woodstox-core, openEuler:22.03-LTS-SP3: woodstox-core, openEuler:20.03-LTS-SP4: woodstox-core&lt;/p&gt;
&lt;p&gt;Woodstox is a high-performance validating namespace-aware StAX-compliant (JSR-173) Open Source XML-processor written in Java. XML processor means that it handles both input (== parsing) and output (== writing, serialization)), as well as supporting tasks such as validation.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.(CVE-2022-40152)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: woodstox-core, openEuler:24.03-LTS: woodstox-core, openEuler:22.03-LTS-SP4: woodstox-core, openEuler:22.03-LTS-SP3: woodstox-core, openEuler:20.03-LTS-SP4: woodstox-core&lt;/p&gt;
&lt;p&gt;Woodstox is a high-performance validating namespace-aware StAX-compliant (JSR-173) Open Source XML-processor written in Java. XML processor means that it handles both input (== parsing) and output (== writing, serialization)), as well as supporting tasks such as validation.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.(CVE-2022-40152)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2378</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13150-1 — jackson-dataformat-xml-2.15.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13150-1</link>
      <description>&lt;p&gt;jackson-dataformat-xml-2.15.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-dataformat-xml-2.15.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13150-1</guid>
    </item>
    <item>
      <title>RHSA-2023:0469 — Red Hat Security Advisory: Red Hat Integration Camel Extensions For Quarkus 2.13.2</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:0469</link>
      <description>&lt;p&gt;jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or JSON data xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS jackson-databind: use of deeply nested arrays apache-commons-text: variable interpolation RCE&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or JSON data xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS jackson-databind: use of deeply nested arrays apache-commons-text: variable interpolation RCE&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:0469</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:0592-1 — Security update for SUSE Manager Server 4.2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:0592-1</link>
      <description>&lt;p&gt;Security update for SUSE Manager Server 4.2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Server 4.2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:0592-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-40152</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-40152</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxstream-java, Ubuntu:Pro:16.04:LTS: libxstream-java, Ubuntu:18.04:LTS: libxstream-java, Ubuntu:20.04:LTS: libxstream-java, Ubuntu:22.04:LTS: libxstream-java, Ubuntu:24.04:LTS: libxstream-java, Ubuntu:25.10: libxstream-java, Ubuntu:26.04:LTS: libxstream-java&lt;/p&gt;
&lt;p&gt;Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxstream-java, Ubuntu:Pro:16.04:LTS: libxstream-java, Ubuntu:18.04:LTS: libxstream-java, Ubuntu:20.04:LTS: libxstream-java, Ubuntu:22.04:LTS: libxstream-java, Ubuntu:24.04:LTS: libxstream-java, Ubuntu:25.10: libxstream-java, Ubuntu:26.04:LTS: libxstream-java&lt;/p&gt;
&lt;p&gt;Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-40152</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0209 — Red Hat Integration Camel Extensions for Quarkus: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0209</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Integration Camel Extensions for Quarkus ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Integration Camel Extensions for Quarkus ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0209</guid>
    </item>
  </channel>
</rss>
