<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:19:32 +0000</lastBuildDate>
    <item>
      <title>certfr-2024-avi-0715 — Une vulnérabilité a été découverte dans Spring Boot. Elle permet à un attaquant de provoquer un contournement de la pol…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0715</link>
      <description>certfr-2024-avi-0715</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0715</guid>
    </item>
    <item>
      <title>EUVD-2026-225735</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-225735</link>
      <description>EUVD-2026-225735</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-225735</guid>
    </item>
    <item>
      <title>fkie_cve-2024-38807</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38807</link>
      <description>&lt;p&gt;Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-38807</guid>
    </item>
    <item>
      <title>GHSA-7cj3-x93g-gj76 — Signature forgery in Spring Boot's Loader</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7cj3-x93g-gj76</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.boot:spring-boot-loader, Maven: org.springframework.boot:spring-boot-loader-classic&lt;/p&gt;
&lt;p&gt;Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.boot:spring-boot-loader, Maven: org.springframework.boot:spring-boot-loader-classic&lt;/p&gt;
&lt;p&gt;Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7cj3-x93g-gj76</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-38807</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38807</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38807</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1916 — VMware Tanzu Spring Boot: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1916</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in VMware Tanzu Spring Boot ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in VMware Tanzu Spring Boot ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1916</guid>
    </item>
  </channel>
</rss>
