<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:15:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-01020</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01020</link>
      <description>bdu:2026-01020</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01020</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0224 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224</link>
      <description>certfr-2026-avi-0224</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AT07752 — Security fix for CVE-2024-29371 applied in: apache-nifi 2.6.0-r3, apache-nifi 2.7.2-r7, confluent-common-docker 7.6.9-r…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-at07752</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi, CleanStart: confluent-common-docker, CleanStart: strimzi-kafka-operator&lt;/p&gt;
&lt;p&gt;CVE-2024-29371 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi, CleanStart: confluent-common-docker, CleanStart: strimzi-kafka-operator&lt;/p&gt;
&lt;p&gt;CVE-2024-29371 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-at07752</guid>
    </item>
    <item>
      <title>EUVD-2026-266472</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266472</link>
      <description>EUVD-2026-266472</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266472</guid>
    </item>
    <item>
      <title>fkie_cve-2024-29371</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29371</link>
      <description>&lt;p&gt;In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-29371</guid>
    </item>
    <item>
      <title>GHSA-3677-xxcr-wjqv — jose4j is vulnerable to DoS via compressed JWE content</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3677-xxcr-wjqv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.bitbucket.b_c:jose4j&lt;/p&gt;
&lt;p&gt;In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.bitbucket.b_c:jose4j&lt;/p&gt;
&lt;p&gt;In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3677-xxcr-wjqv</guid>
    </item>
    <item>
      <title>gsd-2024-29371</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-29371</link>
      <description>gsd-2024-29371</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-29371</guid>
    </item>
    <item>
      <title>RHSA-2024:5479 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.3 Security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:5479</link>
      <description>&lt;p&gt;cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding netty-codec-http: Allocation of Resources Without Limits or Throttling jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack) org.bouncycastle:bcprov-jdk18on: Infinite loop in ED25519 verification in the ScalarUtil class&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cxf-core: Apache CXF SSRF Vulnerability using the Aegis databinding netty-codec-http: Allocation of Resources Without Limits or Throttling jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack) org.bouncycastle:bcprov-jdk18on: Infinite loop in ED25519 verification in the ScalarUtil class&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:5479</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1010-1 — Security update 5.0.7 for Multi-Linux Manager Server</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1010-1</link>
      <description>&lt;p&gt;Security update 5.0.7 for Multi-Linux Manager Server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update 5.0.7 for Multi-Linux Manager Server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1010-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-29371</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-29371</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: libjose4j-java, Ubuntu:24.04:LTS: libjose4j-java, Ubuntu:25.10: libjose4j-java, Ubuntu:26.04:LTS: libjose4j-java&lt;/p&gt;
&lt;p&gt;In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: libjose4j-java, Ubuntu:24.04:LTS: libjose4j-java, Ubuntu:25.10: libjose4j-java, Ubuntu:26.04:LTS: libjose4j-java&lt;/p&gt;
&lt;p&gt;In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-29371</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0517 — IBM WebSphere Application Server und WebSphere Application Server Liberty: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0517</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM WebSphere Application Server und WebSphere Application Server Liberty ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM WebSphere Application Server und WebSphere Application Server Liberty ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0517</guid>
    </item>
  </channel>
</rss>
