<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:32:10 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-03108</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-03108</link>
      <description>bdu:2024-03108</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-03108</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0298 — Une vulnérabilité a été découverte dans&lt;span class="textit"&gt; Spring
Framework&lt;/span&gt;. Elle permet à un attaquant de pro…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0298</link>
      <description>certfr-2024-avi-0298</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0298</guid>
    </item>
    <item>
      <title>EUVD-2026-217192</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217192</link>
      <description>EUVD-2026-217192</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217192</guid>
    </item>
    <item>
      <title>fkie_cve-2024-22262</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-22262</link>
      <description>&lt;p&gt;Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.&lt;/p&gt;
&lt;p&gt;This is the same as  CVE-2024-22259 https://spring.io/security/cve-2024-22259  and  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.&lt;/p&gt;
&lt;p&gt;This is the same as  CVE-2024-22259 https://spring.io/security/cve-2024-22259  and  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-22262</guid>
    </item>
    <item>
      <title>GHSA-2wrp-6fg6-hmc5 — Spring Framework URL Parsing with Host Validation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2wrp-6fg6-hmc5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-web&lt;/p&gt;
&lt;p&gt;Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.&lt;/p&gt;
&lt;p&gt;This is the same as  CVE-2024-22259 https://spring.io/security/cve-2024-22259  and  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-web&lt;/p&gt;
&lt;p&gt;Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.&lt;/p&gt;
&lt;p&gt;This is the same as  CVE-2024-22259 https://spring.io/security/cve-2024-22259  and  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2wrp-6fg6-hmc5</guid>
    </item>
    <item>
      <title>gsd-2024-22262</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-22262</link>
      <description>gsd-2024-22262</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-22262</guid>
    </item>
    <item>
      <title>ICSA-25-261-04 — Multiple Open-Source Software Vulnerabilities in Hitachi Energy Asset Suite Product</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-261-04</link>
      <description>&lt;p&gt;Hitachi Energy is aware of multiple reported vulnerabilities that affect the Asset Suite product versions mentioned in this document below. If exploited these vulnerabilities can potentially impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hitachi Energy is aware of multiple reported vulnerabilities that affect the Asset Suite product versions mentioned in this document below. If exploited these vulnerabilities can potentially impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-261-04</guid>
    </item>
    <item>
      <title>RHSA-2024:3708 — Red Hat Security Advisory: Red Hat Build of Apache Camel 3.20.6 for Spring Boot security update.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3708</link>
      <description>&lt;p&gt;OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data santuario: Private Key disclosure in debug-log output spring-security: Broken Access Control With Direct Use of AuthenticatedVoter springframework: URL Parsing with Host Validation cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data santuario: Private Key disclosure in debug-log output spring-security: Broken Access Control With Direct Use of AuthenticatedVoter springframework: URL Parsing with Host Validation cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3708</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-22262</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-22262</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as  CVE-2024-22259 https://spring.io/security/cve-2024-22259  and  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as  CVE-2024-22259 https://spring.io/security/cve-2024-22259  and  CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-22262</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0854 — VMware Tanzu Spring Framework: Schwachstelle ermöglicht Manipulation von Daten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0854</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Framework ausnutzen, um Daten zu manipulieren oder Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Framework ausnutzen, um Daten zu manipulieren oder Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0854</guid>
    </item>
  </channel>
</rss>
