<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:32:18 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-00177</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-00177</link>
      <description>bdu:2025-00177</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-00177</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0337 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0337</link>
      <description>certfr-2025-avi-0337</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0337</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</guid>
    </item>
    <item>
      <title>EUVD-2026-208886</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-208886</link>
      <description>EUVD-2026-208886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-208886</guid>
    </item>
    <item>
      <title>fkie_cve-2024-12798</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-12798</link>
      <description>&lt;p&gt;ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core
      upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows
      attacker to execute arbitrary code by compromising an existing
      logback configuration file or by injecting an environment variable
      before program execution.&lt;/p&gt;
&lt;p&gt;Malicious logback configuration files can allow the attacker to execute 
arbitrary code using the JaninoEventEvaluator extension.&lt;/p&gt;
&lt;p&gt;A successful attack requires the user to have write access to a 
configuration file. Alternatively, the attacker could inject a malicious 
environment variable pointing to a malicious configuration file. In both 
cases, the attack requires existing privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core
      upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows
      attacker to execute arbitrary code by compromising an existing
      logback configuration file or by injecting an environment variable
      before program execution.&lt;/p&gt;
&lt;p&gt;Malicious logback configuration files can allow the attacker to execute 
arbitrary code using the JaninoEventEvaluator extension.&lt;/p&gt;
&lt;p&gt;A successful attack requires the user to have write access to a 
configuration file. Alternatively, the attacker could inject a malicious 
environment variable pointing to a malicious configuration file. In both 
cases, the attack requires existing privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-12798</guid>
    </item>
    <item>
      <title>GHSA-pr98-23f8-jwxv — QOS.CH logback-core Expression Language Injection vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pr98-23f8-jwxv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: ch.qos.logback:logback-core&lt;/p&gt;
&lt;p&gt;ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core up to and including version 1.5.12 in Java applications allows attackers to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution.&lt;/p&gt;
&lt;p&gt;Malicious logback configuration files can allow the attacker to execute arbitrary code using the JaninoEventEvaluator extension.&lt;/p&gt;
&lt;p&gt;A successful attack requires the user to have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: ch.qos.logback:logback-core&lt;/p&gt;
&lt;p&gt;ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core up to and including version 1.5.12 in Java applications allows attackers to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution.&lt;/p&gt;
&lt;p&gt;Malicious logback configuration files can allow the attacker to execute arbitrary code using the JaninoEventEvaluator extension.&lt;/p&gt;
&lt;p&gt;A successful attack requires the user to have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pr98-23f8-jwxv</guid>
    </item>
    <item>
      <title>jvndb-2026-010300</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-010300</link>
      <description>&lt;p&gt;Hitachi Ops Center Viewpoint contain the following vulnerabilities:&#13;
&#13;
CVE-2014-3643, CVE-2023-3635, CVE-2023-6378, CVE-2023-6481, CVE-2023-35116, CVE-2024-12798, CVE-2024-12801, CVE-2024-47554&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hitachi Ops Center Viewpoint contain the following vulnerabilities:&#13;
&#13;
CVE-2014-3643, CVE-2023-3635, CVE-2023-6378, CVE-2023-6481, CVE-2023-35116, CVE-2024-12798, CVE-2024-12801, CVE-2024-47554&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-010300</guid>
    </item>
    <item>
      <title>OESA-2025-1082 — logback security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1082</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: logback, openEuler:22.03-LTS-SP3: logback, openEuler:22.03-LTS-SP4: logback, openEuler:24.03-LTS: logback, openEuler:24.03-LTS-SP1: logback&lt;/p&gt;
&lt;p&gt;Logback is intended as a successor to the popular log4j project.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core
      upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows
      attacker to execute arbitrary code by compromising an existing
      logback configuration file or by injecting an environment variable
      before program execution.&lt;/p&gt;
&lt;p&gt;Malicious logback configuration files can allow the attacker to execute 
arbitrary code using the JaninoEventEvaluator extension.&lt;/p&gt;
&lt;p&gt;A successful attack requires the user to have write access to a 
configuration file. Alternatively, the attacker could inject a malicious 
environment variable pointing to a malicious configuration file. In both 
cases, the attack requires existing privilege.(CVE-2024-12798)&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to 
forge requests by compromising logback configuration files in XML.&lt;/p&gt;
&lt;p&gt;The attacks involves the modification of DOCTYPE declaration in  XML configuration files.(CVE-2024-12801)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: logback, openEuler:22.03-LTS-SP3: logback, openEuler:22.03-LTS-SP4: logback, openEuler:24.03-LTS: logback, openEuler:24.03-LTS-SP1: logback&lt;/p&gt;
&lt;p&gt;Logback is intended as a successor to the popular log4j project.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core
      upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows
      attacker to execute arbitrary code by compromising an existing
      logback configuration file or by injecting an environment variable
      before program execution.&lt;/p&gt;
&lt;p&gt;Malicious logback configuration files can allow the attacker to execute 
arbitrary code using the JaninoEventEvaluator extension.&lt;/p&gt;
&lt;p&gt;A successful attack requires the user to have write access to a 
configuration file. Alternatively, the attacker could inject a malicious 
environment variable pointing to a malicious configuration file. In both 
cases, the attack requires existing privilege.(CVE-2024-12798)&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to 
forge requests by compromising logback configuration files in XML.&lt;/p&gt;
&lt;p&gt;The attacks involves the modification of DOCTYPE declaration in  XML configuration files.(CVE-2024-12801)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1082</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14627-1 — logback-1.2.11-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14627-1</link>
      <description>&lt;p&gt;logback-1.2.11-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;logback-1.2.11-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14627-1</guid>
    </item>
    <item>
      <title>RHSA-2025:1078 — Red Hat Security Advisory: Red Hat Build of Apache Camel 4.8.3 for Spring Boot security update.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:1078</link>
      <description>&lt;p&gt;logback-core: arbitrary code execution via JaninoEventEvaluator mina-core: Apache MINA: applications using unbounded deserialization may allow RCE async-http-client: AsyncHttpClient (AHC) library&amp;#39;s `CookieStore` replaces explicitly defined `Cookie`s&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;logback-core: arbitrary code execution via JaninoEventEvaluator mina-core: Apache MINA: applications using unbounded deserialization may allow RCE async-http-client: AsyncHttpClient (AHC) library&amp;#39;s `CookieStore` replaces explicitly defined `Cookie`s&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:1078</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0072-1 — Security update for logback</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0072-1</link>
      <description>&lt;p&gt;Security update for logback&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for logback&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0072-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-12798</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12798</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:22.04:LTS: logback, Ubuntu:24.04:LTS: logback&lt;/p&gt;
&lt;p&gt;ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core       upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows       attacker to execute arbitrary code by compromising an existing       logback configuration file or by injecting an environment variable       before program execution. Malicious logback configuration files can allow the attacker to execute arbitrary code using the JaninoEventEvaluator extension. A successful attack requires the user to have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:22.04:LTS: logback, Ubuntu:24.04:LTS: logback&lt;/p&gt;
&lt;p&gt;ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core       upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows       attacker to execute arbitrary code by compromising an existing       logback configuration file or by injecting an environment variable       before program execution. Malicious logback configuration files can allow the attacker to execute arbitrary code using the JaninoEventEvaluator extension. A successful attack requires the user to have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12798</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0284 — Apache Camel for Spring Boot: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0284</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache Camel, Red Hat Enterprise Linux und Red Hat Integration ausnutzen, um beliebigen Code auszuführen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache Camel, Red Hat Enterprise Linux und Red Hat Integration ausnutzen, um beliebigen Code auszuführen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0284</guid>
    </item>
  </channel>
</rss>
