<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 13:02:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-05966</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05966</link>
      <description>bdu:2024-05966</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05966</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0106 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0106</link>
      <description>certfr-2025-avi-0106</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0106</guid>
    </item>
    <item>
      <title>EUVD-2026-201749</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-201749</link>
      <description>EUVD-2026-201749</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-201749</guid>
    </item>
    <item>
      <title>fkie_cve-2024-29736</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29736</link>
      <description>&lt;p&gt;A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-29736</guid>
    </item>
    <item>
      <title>GHSA-5m3j-pxh7-455p — Apache CXF: SSRF vulnerability via WADL stylesheet parameter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5m3j-pxh7-455p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf-rt-rs-service-description&lt;/p&gt;
&lt;p&gt;A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf-rt-rs-service-description&lt;/p&gt;
&lt;p&gt;A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5m3j-pxh7-455p</guid>
    </item>
    <item>
      <title>gsd-2024-29736</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-29736</link>
      <description>gsd-2024-29736</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-29736</guid>
    </item>
    <item>
      <title>RHSA-2024:2707 — Red Hat Security Advisory: Red Hat Build of Apache Camel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:2707</link>
      <description>&lt;p&gt;guava: insecure temporary directory creation xnio: StackOverflowException when the chain of notifier states becomes problematically big jackson-databind: denial of service via cylic dependencies json-path: stack-based buffer overflow in Criteria.parse method tomcat: Leaking of unrelated request bodies in default error page apache: cxf: org.apache.cxf:cxf-rt-rs-service-description: SSRF via WADL stylesheet parameter apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;guava: insecure temporary directory creation xnio: StackOverflowException when the chain of notifier states becomes problematically big jackson-databind: denial of service via cylic dependencies json-path: stack-based buffer overflow in Criteria.parse method tomcat: Leaking of unrelated request bodies in default error page apache: cxf: org.apache.cxf:cxf-rt-rs-service-description: SSRF via WADL stylesheet parameter apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:2707</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1678 — Apache CXF: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1678</link>
      <description>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Apache CXF ausnutzen, um Informationen offenzulegen oder einen Denial-of-Service-Zustand zu erzeugen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Apache CXF ausnutzen, um Informationen offenzulegen oder einen Denial-of-Service-Zustand zu erzeugen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1678</guid>
    </item>
  </channel>
</rss>
