<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:08:59 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-IA43044 — Security fixes for CVE-2020-8908, CVE-2022-42889, CVE-2023-2976, CVE-2024-25710, CVE-2024-26308, CVE-2024-29371, CVE-20…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ia43044</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: strimzi-kafka-operator&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the strimzi-kafka-operator package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: strimzi-kafka-operator&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the strimzi-kafka-operator package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ia43044</guid>
    </item>
    <item>
      <title>EUVD-2026-255366</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255366</link>
      <description>EUVD-2026-255366</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255366</guid>
    </item>
    <item>
      <title>fkie_cve-2024-31573</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-31573</link>
      <description>&lt;p&gt;XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-31573</guid>
    </item>
    <item>
      <title>GHSA-chfm-68vv-pvw5 — XMLUnit for Java has Insecure Defaults when Processing XSLT Stylesheets</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-chfm-68vv-pvw5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xmlunit:xmlunit-core&lt;/p&gt;
&lt;p&gt;### Impact
When performing XSLT transformations XMLUnit for Java did not disable XSLT extension functions by default. Depending on the XSLT processor being used this could allow arbitrary code to be executed when XMLUnit is used to transform data with a stylesheet who&amp;#39;s source can not be trusted. If the stylesheet can be provided externally this may even lead to a remote code execution.&lt;/p&gt;
&lt;p&gt;## Patches
Users are advised to upgrade to XMLUnit for Java 2.10.0 where the default has been changed by means of https://github.com/xmlunit/xmlunit/commit/b81d48b71dfd2868bdfc30a3e17ff973f32bc15b&lt;/p&gt;
&lt;p&gt;### Workarounds
XMLUnit&amp;#39;s main use-case is performing tests on code that generates or processes XML. Most users will not use it to perform arbitrary XSLT transformations.&lt;/p&gt;
&lt;p&gt;Users running XSLT transformations with untrusted stylesheets should explicitly use XMLUnit&amp;#39;s APIs to pass in a pre-configured TraX `TransformerFactory` with extension functions disabled via features and attributes. The required `setFactory` or `setTransformerFactory` methods have been available since XMLUnit for Java 2.0.0.&lt;/p&gt;
&lt;p&gt;### References
[Bug Report](https://github.com/xmlunit/xmlunit/issues/264)
[JAXP Security Guide](https://docs.oracle.com/en/java/javase/22/security/java-api-xml-processing-jaxp-security-guide.html#GUID-E345AA09-801E-4B95-B83D-7F0C452538AA)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xmlunit:xmlunit-core&lt;/p&gt;
&lt;p&gt;### Impact
When performing XSLT transformations XMLUnit for Java did not disable XSLT extension functions by default. Depending on the XSLT processor being used this could allow arbitrary code to be executed when XMLUnit is used to transform data with a stylesheet who&amp;#39;s source can not be trusted. If the stylesheet can be provided externally this may even lead to a remote code execution.&lt;/p&gt;
&lt;p&gt;## Patches
Users are advised to upgrade to XMLUnit for Java 2.10.0 where the default has been changed by means of https://github.com/xmlunit/xmlunit/commit/b81d48b71dfd2868bdfc30a3e17ff973f32bc15b&lt;/p&gt;
&lt;p&gt;### Workarounds
XMLUnit&amp;#39;s main use-case is performing tests on code that generates or processes XML. Most users will not use it to perform arbitrary XSLT transformations.&lt;/p&gt;
&lt;p&gt;Users running XSLT transformations with untrusted stylesheets should explicitly use XMLUnit&amp;#39;s APIs to pass in a pre-configured TraX `TransformerFactory` with extension functions disabled via features and attributes. The required `setFactory` or `setTransformerFactory` methods have been available since XMLUnit for Java 2.0.0.&lt;/p&gt;
&lt;p&gt;### References
[Bug Report](https://github.com/xmlunit/xmlunit/issues/264)
[JAXP Security Guide](https://docs.oracle.com/en/java/javase/22/security/java-api-xml-processing-jaxp-security-guide.html#GUID-E345AA09-801E-4B95-B83D-7F0C452538AA)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-chfm-68vv-pvw5</guid>
    </item>
    <item>
      <title>gsd-2024-31573</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-31573</link>
      <description>gsd-2024-31573</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-31573</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-31573 — XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (u…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-31573</link>
      <description>msrc_CVE-2024-31573</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-31573</guid>
    </item>
    <item>
      <title>OESA-2025-1966 — xmlunit security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1966</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: xmlunit&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in xmlunit-core. It has been declared as problematic.As an impact it is known to affect confidentiality, integrity, and availability.Upgrading to version 2.10.0 eliminates this vulnerability.(CVE-2024-31573)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: xmlunit&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in xmlunit-core. It has been declared as problematic.As an impact it is known to affect confidentiality, integrity, and availability.Upgrading to version 2.10.0 eliminates this vulnerability.(CVE-2024-31573)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1966</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-31573</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-31573</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: xmlunit, Ubuntu:18.04:LTS: xmlunit, Ubuntu:20.04:LTS: xmlunit, Ubuntu:22.04:LTS: xmlunit, Ubuntu:24.04:LTS: xmlunit, Ubuntu:25.10: xmlunit, Ubuntu:26.04:LTS: xmlunit&lt;/p&gt;
&lt;p&gt;XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: xmlunit, Ubuntu:18.04:LTS: xmlunit, Ubuntu:20.04:LTS: xmlunit, Ubuntu:22.04:LTS: xmlunit, Ubuntu:24.04:LTS: xmlunit, Ubuntu:25.10: xmlunit, Ubuntu:26.04:LTS: xmlunit&lt;/p&gt;
&lt;p&gt;XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-31573</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1203 — Oracle Fusion Middleware: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1203</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1203</guid>
    </item>
  </channel>
</rss>
