<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:24:50 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-08042</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08042</link>
      <description>bdu:2023-08042</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08042</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0860 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0860</link>
      <description>certfr-2023-avi-0860</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0860</guid>
    </item>
    <item>
      <title>EUVD-2026-216070</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216070</link>
      <description>EUVD-2026-216070</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216070</guid>
    </item>
    <item>
      <title>fkie_cve-2022-44729</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-44729</link>
      <description>&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.&lt;/p&gt;
&lt;p&gt;On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.&lt;/p&gt;
&lt;p&gt;On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-44729</guid>
    </item>
    <item>
      <title>GHSA-gq5f-xv48-2365 — Apache XML Graphics Batik Server-Side Request Forgery vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gq5f-xv48-2365</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.xmlgraphics:batik-bridge, Maven: org.apache.xmlgraphics:batik-svgrasterizer, Maven: org.apache.xmlgraphics:batik-transcoder&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.&lt;/p&gt;
&lt;p&gt;On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.xmlgraphics:batik-bridge, Maven: org.apache.xmlgraphics:batik-svgrasterizer, Maven: org.apache.xmlgraphics:batik-transcoder&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.&lt;/p&gt;
&lt;p&gt;On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gq5f-xv48-2365</guid>
    </item>
    <item>
      <title>gsd-2022-44729</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-44729</link>
      <description>gsd-2022-44729</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-44729</guid>
    </item>
    <item>
      <title>ICSA-25-261-04 — Multiple Open-Source Software Vulnerabilities in Hitachi Energy Asset Suite Product</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-261-04</link>
      <description>&lt;p&gt;Hitachi Energy is aware of multiple reported vulnerabilities that affect the Asset Suite product versions mentioned in this document below. If exploited these vulnerabilities can potentially impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hitachi Energy is aware of multiple reported vulnerabilities that affect the Asset Suite product versions mentioned in this document below. If exploited these vulnerabilities can potentially impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-261-04</guid>
    </item>
    <item>
      <title>OESA-2023-1651 — batik security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1651</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: batik, openEuler:20.03-LTS-SP3: batik, openEuler:22.03-LTS: batik, openEuler:22.03-LTS-SP1: batik, openEuler:22.03-LTS-SP2: batik&lt;/p&gt;
&lt;p&gt;Batik is an inline templating engine for CoffeeScript, inspired by CoffeeKup,  that lets you write your template directly as a CoffeeScript function.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.(CVE-2022-38398)&#13;
&#13;
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.(CVE-2022-38648)&#13;
&#13;
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.(CVE-2022-40146)&#13;
&#13;
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.&#13;
&#13;
On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.&#13;
&#13;
(CVE-2022-44729)&#13;
&#13;
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.&#13;
&#13;
A malicious SVG can probe user profile / data and send it directly as parameter to a URL.&#13;
&#13;
(CVE-2022-44730)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: batik, openEuler:20.03-LTS-SP3: batik, openEuler:22.03-LTS: batik, openEuler:22.03-LTS-SP1: batik, openEuler:22.03-LTS-SP2: batik&lt;/p&gt;
&lt;p&gt;Batik is an inline templating engine for CoffeeScript, inspired by CoffeeKup,  that lets you write your template directly as a CoffeeScript function.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.(CVE-2022-38398)&#13;
&#13;
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.(CVE-2022-38648)&#13;
&#13;
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.(CVE-2022-40146)&#13;
&#13;
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.&#13;
&#13;
On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.&#13;
&#13;
(CVE-2022-44729)&#13;
&#13;
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.&#13;
&#13;
A malicious SVG can probe user profile / data and send it directly as parameter to a URL.&#13;
&#13;
(CVE-2022-44730)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1651</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13743-1 — xmlgraphics-batik-1.17-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13743-1</link>
      <description>&lt;p&gt;xmlgraphics-batik-1.17-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmlgraphics-batik-1.17-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13743-1</guid>
    </item>
    <item>
      <title>RHSA-2023:5441 — Red Hat Security Advisory: Red Hat Integration Camel for Spring Boot 4.0.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:5441</link>
      <description>&lt;p&gt;batik: Server-Side Request Forgery vulnerability batik: Server-Side Request Forgery vulnerability apache-ivy: XML External Entity vulnerability jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies apache-johnzon: Prevent inefficient internal conversion from BigDecimal at large scale netty: SniHandler 16MB allocation leads to OOM jetty: Improper validation of HTTP/1 content-length&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;batik: Server-Side Request Forgery vulnerability batik: Server-Side Request Forgery vulnerability apache-ivy: XML External Entity vulnerability jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies apache-johnzon: Prevent inefficient internal conversion from BigDecimal at large scale netty: SniHandler 16MB allocation leads to OOM jetty: Improper validation of HTTP/1 content-length&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:5441</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:0777-1 — Security update for xmlgraphics-batik</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:0777-1</link>
      <description>&lt;p&gt;Security update for xmlgraphics-batik&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for xmlgraphics-batik&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:0777-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-44729</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-44729</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: batik, Ubuntu:18.04:LTS: batik, Ubuntu:20.04:LTS: batik, Ubuntu:22.04:LTS: batik, Ubuntu:24.04:LTS: batik, Ubuntu:25.10: batik, Ubuntu:26.04:LTS: batik&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: batik, Ubuntu:18.04:LTS: batik, Ubuntu:20.04:LTS: batik, Ubuntu:22.04:LTS: batik, Ubuntu:24.04:LTS: batik, Ubuntu:25.10: batik, Ubuntu:26.04:LTS: batik&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-44729</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2673 — Oracle Database Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2673</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Database Server ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Database Server ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2673</guid>
    </item>
  </channel>
</rss>
