<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:33:45 +0000</lastBuildDate>
    <item>
      <title>certfr-2024-avi-0090 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0090</link>
      <description>certfr-2024-avi-0090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0090</guid>
    </item>
    <item>
      <title>EUVD-2026-227926</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-227926</link>
      <description>EUVD-2026-227926</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-227926</guid>
    </item>
    <item>
      <title>fkie_cve-2023-0105</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0105</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-0105</guid>
    </item>
    <item>
      <title>GHSA-c7xw-p58w-h6fj — Keycloak: Impersonation and lockout possible through incorrect handling of email trust</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c7xw-p58w-h6fj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;Impersonation and lockout are possible due to email trust not being handled correctly in Keycloak. Since the verified state is not reset when the email changes, it is possible for users to shadow others with the same email and lock out or impersonate them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;Impersonation and lockout are possible due to email trust not being handled correctly in Keycloak. Since the verified state is not reset when the email changes, it is possible for users to shadow others with the same email and lock out or impersonate them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c7xw-p58w-h6fj</guid>
    </item>
    <item>
      <title>gsd-2023-0105</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-0105</link>
      <description>gsd-2023-0105</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-0105</guid>
    </item>
    <item>
      <title>RHSA-2023:7482 — Red Hat Security Advisory: Red Hat Single Sign-On 7.6.6 security update on RHEL 7</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:7482</link>
      <description>&lt;p&gt;keycloak: impersonation and lockout possible through incorrect handling of email trust bouncycastle: potential  blind LDAP injection attack using a self-signed certificate HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;keycloak: impersonation and lockout possible through incorrect handling of email trust bouncycastle: potential  blind LDAP injection attack using a self-signed certificate HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:7482</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0036 — Keycloak: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0036</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Sicherheitsvorkehrungen zu umgehen und dadurch Nutzerrechte zu erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Sicherheitsvorkehrungen zu umgehen und dadurch Nutzerrechte zu erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0036</guid>
    </item>
  </channel>
</rss>
