<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:19:38 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BA48144 — Security fixes in keycloak 26.5.7-r5</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ba48144</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: keycloak&lt;/p&gt;
&lt;p&gt;Package keycloak version 26.5.7-r5 fixes 11 vulnerabilities: CVE-2026-54291, CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: keycloak&lt;/p&gt;
&lt;p&gt;Package keycloak version 26.5.7-r5 fixes 11 vulnerabilities: CVE-2026-54291, CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ba48144</guid>
    </item>
    <item>
      <title>EUVD-2026-363697</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363697</link>
      <description>EUVD-2026-363697</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363697</guid>
    </item>
    <item>
      <title>fkie_cve-2025-11537</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-11537</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined &amp;#39;long&amp;#39; pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined &amp;#39;long&amp;#39; pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-11537</guid>
    </item>
    <item>
      <title>GHSA-gv3v-2cpp-3pmq — Keycloak logs sensitive headers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gv3v-2cpp-3pmq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-quarkus-server&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined &amp;#39;long&amp;#39; pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.&lt;/p&gt;
&lt;p&gt;Patches are available, see:&lt;/p&gt;
&lt;p&gt;- https://github.com/keycloak/keycloak/releases/tag/26.4.11
- https://github.com/keycloak/keycloak/releases/tag/26.5.6
- https://github.com/keycloak/keycloak/releases/tag/26.6.0&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-quarkus-server&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined &amp;#39;long&amp;#39; pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.&lt;/p&gt;
&lt;p&gt;Patches are available, see:&lt;/p&gt;
&lt;p&gt;- https://github.com/keycloak/keycloak/releases/tag/26.4.11
- https://github.com/keycloak/keycloak/releases/tag/26.5.6
- https://github.com/keycloak/keycloak/releases/tag/26.6.0&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gv3v-2cpp-3pmq</guid>
    </item>
    <item>
      <title>jvndb-2026-026852</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-026852</link>
      <description>&lt;p&gt;Multiple vulnerabilities exist in Hitachi Ops Center Common Services.&#13;
&#13;
CVE-2025-10939, CVE-2025-11537, CVE-2025-11538, CVE-2025-12110, CVE-2025-13467, CVE-2025-13881, CVE-2025-14082, CVE-2025-14083, CVE-2025-14777, CVE-2025-66560, CVE-2026-0707, CVE-2026-0871, CVE-2026-0976, CVE-2026-1035, CVE-2026-1190, CVE-2026-2092, CVE-2026-2575, CVE-2026-2673, CVE-2026-3009, CVE-2026-3121, CVE-2026-3429, CVE-2026-3872, CVE-2026-3911, CVE-2026-4282, CVE-2026-4325, CVE-2026-4634, CVE-2026-22745, CVE-2026-22748, CVE-2026-25854, CVE-2026-40972, CVE-2026-40975&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities exist in Hitachi Ops Center Common Services.&#13;
&#13;
CVE-2025-10939, CVE-2025-11537, CVE-2025-11538, CVE-2025-12110, CVE-2025-13467, CVE-2025-13881, CVE-2025-14082, CVE-2025-14083, CVE-2025-14777, CVE-2025-66560, CVE-2026-0707, CVE-2026-0871, CVE-2026-0976, CVE-2026-1035, CVE-2026-1190, CVE-2026-2092, CVE-2026-2575, CVE-2026-2673, CVE-2026-3009, CVE-2026-3121, CVE-2026-3429, CVE-2026-3872, CVE-2026-3911, CVE-2026-4282, CVE-2026-4325, CVE-2026-4634, CVE-2026-22745, CVE-2026-22748, CVE-2026-25854, CVE-2026-40972, CVE-2026-40975&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-026852</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0394 — Keycloak: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0394</link>
      <description>&lt;p&gt;Ein lokaler, oder entfernter authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler, oder entfernter authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0394</guid>
    </item>
  </channel>
</rss>
