<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:25:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-08726</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-08726</link>
      <description>bdu:2024-08726</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-08726</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0900 — De multiples vulnérabilités ont été découvertes dans Spring Framework. Elles permettent à un attaquant de provoquer une…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0900</link>
      <description>certfr-2024-avi-0900</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0900</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-HW70472 — Security fixes in activemq 5.19.8-r3</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-hw70472</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: activemq&lt;/p&gt;
&lt;p&gt;Package activemq version 5.19.8-r3 fixes 29 vulnerabilities: CVE-2016-1000027, CVE-2024-38816, CVE-2024-38819, CVE-2024-38820, CVE-2024-38827...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: activemq&lt;/p&gt;
&lt;p&gt;Package activemq version 5.19.8-r3 fixes 29 vulnerabilities: CVE-2016-1000027, CVE-2024-38816, CVE-2024-38819, CVE-2024-38820, CVE-2024-38827...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-hw70472</guid>
    </item>
    <item>
      <title>EUVD-2026-209953</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-209953</link>
      <description>EUVD-2026-209953</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-209953</guid>
    </item>
    <item>
      <title>fkie_cve-2024-38819</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38819</link>
      <description>&lt;p&gt;Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-38819</guid>
    </item>
    <item>
      <title>GHSA-g5vr-rgqm-vf78 — Spring Framework Path Traversal vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g5vr-rgqm-vf78</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-webflux, Maven: org.springframework:spring-webmvc&lt;/p&gt;
&lt;p&gt;Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-webflux, Maven: org.springframework:spring-webmvc&lt;/p&gt;
&lt;p&gt;Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g5vr-rgqm-vf78</guid>
    </item>
    <item>
      <title>RHSA-2024:10700 — Red Hat Security Advisory: Red Hat Build of Apache Camel 4.8 for Spring Boot security update.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:10700</link>
      <description>&lt;p&gt;protobuf: StackOverflow vulnerability in Protocol Buffers kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;protobuf: StackOverflow vulnerability in Protocol Buffers kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:10700</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-38819</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38819</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38819</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3237 — VMware Tanzu Spring Framework: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3237</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Framework ausnutzen, um Informationen offenzulegen oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Framework ausnutzen, um Informationen offenzulegen oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3237</guid>
    </item>
  </channel>
</rss>
