<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:32:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-03597</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-03597</link>
      <description>bdu:2024-03597</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-03597</guid>
    </item>
    <item>
      <title>BIT-tomcat-2022-45143 — Apache Tomcat: JsonErrorReportValve escaping</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2022-45143</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2022-45143</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0001 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un
attaquant de provoquer un problème de sécurité…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0001</link>
      <description>certfr-2023-avi-0001</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0001</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AJ47488 — When using the RemoteIpFilter with requests received from a    reverse proxy via HTTP that include the X-Forwarded-Prot…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aj47488</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tomcat10&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the tomcat10 package. When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tomcat10&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the tomcat10 package. When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aj47488</guid>
    </item>
    <item>
      <title>EUVD-2026-19668</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-19668</link>
      <description>EUVD-2026-19668</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-19668</guid>
    </item>
    <item>
      <title>fkie_cve-2022-45143</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-45143</link>
      <description>&lt;p&gt;The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-45143</guid>
    </item>
    <item>
      <title>GHSA-rq2w-37h9-vg94 — Apache Tomcat improperly escapes input from JsonErrorReportValve</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rq2w-37h9-vg94</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat:tomcat-util&lt;/p&gt;
&lt;p&gt;The `JsonErrorReportValve` in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 does not escape the `type`, `message` or `description` values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat:tomcat-util&lt;/p&gt;
&lt;p&gt;The `JsonErrorReportValve` in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 does not escape the `type`, `message` or `description` values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rq2w-37h9-vg94</guid>
    </item>
    <item>
      <title>gsd-2022-45143</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-45143</link>
      <description>gsd-2022-45143</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-45143</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12847-1 — tomcat-9.0.43-16.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12847-1</link>
      <description>&lt;p&gt;tomcat-9.0.43-16.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat-9.0.43-16.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12847-1</guid>
    </item>
    <item>
      <title>RHSA-2023:1663 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.2 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1663</link>
      <description>&lt;p&gt;tomcat: request smuggling tomcat: JsonErrorReportValve injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: request smuggling tomcat: JsonErrorReportValve injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1663</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-45143</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-45143</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-45143</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0017 — Apache Tomcat: Schwachstelle ermöglicht Manipulation von Daten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0017</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0017</guid>
    </item>
  </channel>
</rss>
