<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:51:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-161838</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-161838</link>
      <description>EUVD-2026-161838</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-161838</guid>
    </item>
    <item>
      <title>fkie_cve-2024-45294</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45294</link>
      <description>&lt;p&gt;The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. Prior to version 6.3.23, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This issue has been patched in release 6.3.23. No known workarounds are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. Prior to version 6.3.23, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This issue has been patched in release 6.3.23. No known workarounds are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-45294</guid>
    </item>
    <item>
      <title>GHSA-6cr6-ph3p-f5rf — XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6cr6-ph3p-f5rf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.dstu3, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.r4, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.r4b, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.r5, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.utilities&lt;/p&gt;
&lt;p&gt;### Impact
XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( `&amp;lt;!DOCTYPE foo [&amp;lt;!ENTITY example SYSTEM &amp;#34;/etc/passwd&amp;#34;&amp;gt; ]&amp;gt;` could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML.&lt;/p&gt;
&lt;p&gt;### Patches
This issue has been patched in release 6.3.23&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
[MITRE CWE](https://cwe.mitre.org/data/definitions/611.html)
[OWASP XML External Entity Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#transformerfactory)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.dstu3, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.r4, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.r4b, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.r5, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.utilities&lt;/p&gt;
&lt;p&gt;### Impact
XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( `&amp;lt;!DOCTYPE foo [&amp;lt;!ENTITY example SYSTEM &amp;#34;/etc/passwd&amp;#34;&amp;gt; ]&amp;gt;` could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML.&lt;/p&gt;
&lt;p&gt;### Patches
This issue has been patched in release 6.3.23&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
[MITRE CWE](https://cwe.mitre.org/data/definitions/611.html)
[OWASP XML External Entity Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#transformerfactory)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6cr6-ph3p-f5rf</guid>
    </item>
    <item>
      <title>RHSA-2024:6883 — Red Hat Security Advisory: Red Hat Build of Apache Camel 3.20.7 for Spring Boot security update.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6883</link>
      <description>&lt;p&gt;nimbus-jose-jwt: large JWE p2c header value causes Denial of Service undertow: response write hangs in case of Java 17 TLSv1.3 NewSessionTicket undertow: Improper State Management in Proxy Protocol parsing causes information leakage apache: cxf: org.apache.cxf:cxf-rt-rs-service-description: SSRF via WADL stylesheet parameter apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE org.hl7.fhir.core: org.hl7.fhir.dstu3: org.hl7.fhir.r4: org.hl7.fhir.r4b: org.hl7.fhir.r5: org.hl7.fhir.utilities: XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nimbus-jose-jwt: large JWE p2c header value causes Denial of Service undertow: response write hangs in case of Java 17 TLSv1.3 NewSessionTicket undertow: Improper State Management in Proxy Protocol parsing causes information leakage apache: cxf: org.apache.cxf:cxf-rt-rs-service-description: SSRF via WADL stylesheet parameter apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE org.hl7.fhir.core: org.hl7.fhir.dstu3: org.hl7.fhir.r4: org.hl7.fhir.r4b: org.hl7.fhir.r5: org.hl7.fhir.utilities: XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6883</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3180 — Apache Camel und mehrere Red Hat Produkte: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3180</link>
      <description>&lt;p&gt;Ein entfernter anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Apache Camel und in mehreren Red Hat-Produkten ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen preiszugeben und beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Apache Camel und in mehreren Red Hat-Produkten ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen preiszugeben und beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3180</guid>
    </item>
  </channel>
</rss>
