<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:12:00 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-233335</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-233335</link>
      <description>EUVD-2026-233335</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-233335</guid>
    </item>
    <item>
      <title>fkie_cve-2022-46166</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-46166</link>
      <description>&lt;p&gt;Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-46166</guid>
    </item>
    <item>
      <title>GHSA-w3x5-427h-wfq6 — Spring Boot Admins integrated notifier support allows arbitrary code execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w3x5-427h-wfq6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: de.codecentric:spring-boot-admin&lt;/p&gt;
&lt;p&gt;### Impact
All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are possibly affected.&lt;/p&gt;
&lt;p&gt;### Patches
In the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 the issue is fixed by implementing `SimpleExecutionContext` of SpEL. This prevents the arbitrary code execution (i.e. SpEL injection).&lt;/p&gt;
&lt;p&gt;### Workarounds
 * Disable any notifier
 * Disable write access (POST request) on `/env` actuator endpoint&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: de.codecentric:spring-boot-admin&lt;/p&gt;
&lt;p&gt;### Impact
All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are possibly affected.&lt;/p&gt;
&lt;p&gt;### Patches
In the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 the issue is fixed by implementing `SimpleExecutionContext` of SpEL. This prevents the arbitrary code execution (i.e. SpEL injection).&lt;/p&gt;
&lt;p&gt;### Workarounds
 * Disable any notifier
 * Disable write access (POST request) on `/env` actuator endpoint&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w3x5-427h-wfq6</guid>
    </item>
    <item>
      <title>gsd-2022-46166</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-46166</link>
      <description>gsd-2022-46166</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-46166</guid>
    </item>
  </channel>
</rss>
