<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:30:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-10117</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-10117</link>
      <description>bdu:2024-10117</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-10117</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0210 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0210</link>
      <description>certfr-2025-avi-0210</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0210</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AO61361 — Security fixes for CVE-2024-6763, CVE-2025-11143, CVE-2025-12183, CVE-2025-12383, CVE-2025-66566, CVE-2025-67030, CVE-2…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ao61361</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kafka-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the kafka-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kafka-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the kafka-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ao61361</guid>
    </item>
    <item>
      <title>EUVD-2026-221219</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-221219</link>
      <description>EUVD-2026-221219</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-221219</guid>
    </item>
    <item>
      <title>fkie_cve-2024-6763</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-6763</link>
      <description>&lt;p&gt;Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.&lt;/p&gt;
&lt;p&gt;The HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI
 differs from the common browsers in how it handles a URI that would be 
considered invalid if fully validated against the RRC.  Specifically HttpURI
 and the browser may differ on the value of the host extracted from an 
invalid URI and thus a combination of Jetty and a vulnerable browser may
 be vulnerable to a open redirect attack or to a SSRF attack if the URI 
is used after passing validation checks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.&lt;/p&gt;
&lt;p&gt;The HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI
 differs from the common browsers in how it handles a URI that would be 
considered invalid if fully validated against the RRC.  Specifically HttpURI
 and the browser may differ on the value of the host extracted from an 
invalid URI and thus a combination of Jetty and a vulnerable browser may
 be vulnerable to a open redirect attack or to a SSRF attack if the URI 
is used after passing validation checks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-6763</guid>
    </item>
    <item>
      <title>GHSA-qh8g-58pp-2wxh — Eclipse Jetty URI parsing of invalid authority</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qh8g-58pp-2wxh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty:jetty-http&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, `HttpURI`, for URI/URL parsing.&lt;/p&gt;
&lt;p&gt;The `HttpURI` class does insufficient validation on the authority segment of a URI.  However the behaviour of `HttpURI` differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC.  Specifically `HttpURI` and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Affected components&lt;/p&gt;
&lt;p&gt;The vulnerable component is the `HttpURI` class when used as a utility class in an application.  The Jetty usage of the class is not vulnerable.&lt;/p&gt;
&lt;p&gt;### Attack overview&lt;/p&gt;
&lt;p&gt;The `HttpURI` class does not well validate the authority section of a URI. When presented with an illegal authority that may contain user info (eg username:password#@hostname:port), then the parsing of the URI is not failed.  Moreover, the interpretation of what part of the authority is the host name differs from a common browser in  that they also do not fail, but they select a different host name from the illegal URI.&lt;/p&gt;
&lt;p&gt;### Attack scenario&lt;/p&gt;
&lt;p&gt;A typical attack scenario is illustrated in the diagram below. The Validator checks whether the attacker-supplied URL is on the blocklist. If not, the URI is…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty:jetty-http&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, `HttpURI`, for URI/URL parsing.&lt;/p&gt;
&lt;p&gt;The `HttpURI` class does insufficient validation on the authority segment of a URI.  However the behaviour of `HttpURI` differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC.  Specifically `HttpURI` and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Affected components&lt;/p&gt;
&lt;p&gt;The vulnerable component is the `HttpURI` class when used as a utility class in an application.  The Jetty usage of the class is not vulnerable.&lt;/p&gt;
&lt;p&gt;### Attack overview&lt;/p&gt;
&lt;p&gt;The `HttpURI` class does not well validate the authority section of a URI. When presented with an illegal authority that may contain user info (eg username:password#@hostname:port), then the parsing of the URI is not failed.  Moreover, the interpretation of what part of the authority is the host name differs from a common browser in  that they also do not fail, but they select a different host name from the illegal URI.&lt;/p&gt;
&lt;p&gt;### Attack scenario&lt;/p&gt;
&lt;p&gt;A typical attack scenario is illustrated in the diagram below. The Validator checks whether the attacker-supplied URL is on the blocklist. If not, the URI is…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qh8g-58pp-2wxh</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15160-1 — jetty-annotations-9.4.57-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15160-1</link>
      <description>&lt;p&gt;jetty-annotations-9.4.57-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jetty-annotations-9.4.57-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15160-1</guid>
    </item>
    <item>
      <title>RHSA-2025:12511 — Red Hat Security Advisory: Streams for Apache Kafka 3.0.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:12511</link>
      <description>&lt;p&gt;json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority jetty-server: Jetty: Gzip Request Body Buffer Corruption kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider netty: Denial of Service attack on windows app using Netty kafka: Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout io.netty:netty-handler: SslHandler doesn&amp;#39;t correctly validate packets which can lead to native crash when using native SSLEngine netty: Denial of Service attack on windows app using Netty commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang io.quarkus/quarkus-vertx: Quarkus potential data leak com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority jetty-server: Jetty: Gzip Request Body Buffer Corruption kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider netty: Denial of Service attack on windows app using Netty kafka: Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout io.netty:netty-handler: SslHandler doesn&amp;#39;t correctly validate packets which can lead to native crash when using native SSLEngine netty: Denial of Service attack on windows app using Netty commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang io.quarkus/quarkus-vertx: Quarkus potential data leak com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:12511</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-6763</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6763</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: jetty, Ubuntu:16.04:LTS: jetty, Ubuntu:16.04:LTS: jetty9, Ubuntu:18.04:LTS: jetty9, Ubuntu:20.04:LTS: jetty9, Ubuntu:22.04:LTS: jetty9, Ubuntu:24.04:LTS: jetty9&lt;/p&gt;
&lt;p&gt;Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI  differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC.  Specifically HttpURI  and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may  be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: jetty, Ubuntu:16.04:LTS: jetty, Ubuntu:16.04:LTS: jetty9, Ubuntu:18.04:LTS: jetty9, Ubuntu:20.04:LTS: jetty9, Ubuntu:22.04:LTS: jetty9, Ubuntu:24.04:LTS: jetty9&lt;/p&gt;
&lt;p&gt;Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI  differs from the common browsers in how it handles a URI that would be considered invalid if fully validated against the RRC.  Specifically HttpURI  and the browser may differ on the value of the host extracted from an invalid URI and thus a combination of Jetty and a vulnerable browser may  be vulnerable to a open redirect attack or to a SSRF attack if the URI is used after passing validation checks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6763</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3176 — Eclipse Jetty: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3176</link>
      <description>&lt;p&gt;Ein entfernter anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um einen Denial of Service Angriff zu erzeugen und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um einen Denial of Service Angriff zu erzeugen und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3176</guid>
    </item>
  </channel>
</rss>
