<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:29:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-227951</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-227951</link>
      <description>EUVD-2026-227951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-227951</guid>
    </item>
    <item>
      <title>fkie_cve-2023-0091</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0091</link>
      <description>&lt;p&gt;A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-0091</guid>
    </item>
    <item>
      <title>GHSA-v436-q368-hvgg — Keycloak has lack of validation of access token on client registrations endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v436-q368-hvgg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;When a service account with the create-client or manage-clients role can use the client-registration endpoints to create/manage clients with an access token.&lt;/p&gt;
&lt;p&gt;If the access token is leaked, there is an option to revoke the specific token. However, the check is not performed in client-registration endpoints.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;When a service account with the create-client or manage-clients role can use the client-registration endpoints to create/manage clients with an access token.&lt;/p&gt;
&lt;p&gt;If the access token is leaked, there is an option to revoke the specific token. However, the check is not performed in client-registration endpoints.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v436-q368-hvgg</guid>
    </item>
    <item>
      <title>gsd-2023-0091</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-0091</link>
      <description>gsd-2023-0091</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-0091</guid>
    </item>
    <item>
      <title>RHSA-2023:1043 — Red Hat Security Advisory: Red Hat Single Sign-On 7.6.2 security update on RHEL 7</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1043</link>
      <description>&lt;p&gt;bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip jquery: Prototype pollution in object&amp;#39;s prototype leading to denial of service, remote code execution, or property injection jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods glob-parent: Regular Expression Denial of Service minimist: prototype pollution keycloak: HTML injection in execute-actions-email Admin REST API keycloak: XSS on impersonation under specific circumstances SnakeYaml: Constructor Deserialization Remote Code Execution Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations keycloak: Session takeover with OIDC offline refreshtokens keycloak: reflected XSS attack Moment.js: Path traversal  in moment.locale snakeyaml: Denial of Service due to missing nested depth limitation for collections moment: inefficient parsing algorithm resulting in DoS loader-utils: Regular expression denial of service snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or J…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip jquery: Prototype pollution in object&amp;#39;s prototype leading to denial of service, remote code execution, or property injection jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods glob-parent: Regular Expression Denial of Service minimist: prototype pollution keycloak: HTML injection in execute-actions-email Admin REST API keycloak: XSS on impersonation under specific circumstances SnakeYaml: Constructor Deserialization Remote Code Execution Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations keycloak: Session takeover with OIDC offline refreshtokens keycloak: reflected XSS attack Moment.js: Path traversal  in moment.locale snakeyaml: Denial of Service due to missing nested depth limitation for collections moment: inefficient parsing algorithm resulting in DoS loader-utils: Regular expression denial of service snakeyaml: Uncaught exception in org.yaml.snakeyaml.composer.Composer.composeSequenceNode snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match jettison: parser crash by stackoverflow jettison: memory exhaustion via user-supplied XML or J…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1043</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0034 — Keycloak: Schwachstelle ermöglicht Manipulation von Daten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0034</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0034</guid>
    </item>
  </channel>
</rss>
