<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:38:01 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10867</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10867</link>
      <description>bdu:2026-10867</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10867</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</link>
      <description>certfr-2026-avi-0667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-QQ48355 — Security fixes in kserve-modelmesh 0.12.0-r17</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-qq48355</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kserve-modelmesh&lt;/p&gt;
&lt;p&gt;Package kserve-modelmesh version 0.12.0-r17 fixes 53 vulnerabilities: ghsa-f6hv-jmp6-3vwv, ghsa-57rv-r2g8-2cj3, ghsa-xxqh-mfjm-7mv9, ghsa-m4cv-j2px-7723, ghsa-v8h7-rr48-vmmv...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kserve-modelmesh&lt;/p&gt;
&lt;p&gt;Package kserve-modelmesh version 0.12.0-r17 fixes 53 vulnerabilities: ghsa-f6hv-jmp6-3vwv, ghsa-57rv-r2g8-2cj3, ghsa-xxqh-mfjm-7mv9, ghsa-m4cv-j2px-7723, ghsa-v8h7-rr48-vmmv...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-qq48355</guid>
    </item>
    <item>
      <title>EUVD-2026-371779</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371779</link>
      <description>EUVD-2026-371779</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371779</guid>
    </item>
    <item>
      <title>fkie_cve-2025-14813</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14813</link>
      <description>&lt;p&gt;: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files G3413CTRBlockCipher.&lt;/p&gt;
&lt;p&gt;This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files G3413CTRBlockCipher.&lt;/p&gt;
&lt;p&gt;This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-14813</guid>
    </item>
    <item>
      <title>GHSA-574f-3g2m-x479 — Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-574f-3g2m-x479</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.bouncycastle:bcprov-jdk14, Maven: org.bouncycastle:bcprov-jdk15to18, Maven: org.bouncycastle:bcprov-jdk18on, Maven: org.bouncycastle:bcprov-debug-jdk14, Maven: org.bouncycastle:bcprov-debug-jdk15to18, Maven: org.bouncycastle:bcprov-debug-jdk18on, Maven: org.bouncycastle:bcprov-ext-jdk14, Maven: org.bouncycastle:bcprov-ext-jdk15to18, Maven: org.bouncycastle:bcprov-ext-jdk18on, Maven: org.bouncycastle:bcprov-ext-debug-jdk14 and 4 more&lt;/p&gt;
&lt;p&gt;The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.bouncycastle:bcprov-jdk14, Maven: org.bouncycastle:bcprov-jdk15to18, Maven: org.bouncycastle:bcprov-jdk18on, Maven: org.bouncycastle:bcprov-debug-jdk14, Maven: org.bouncycastle:bcprov-debug-jdk15to18, Maven: org.bouncycastle:bcprov-debug-jdk18on, Maven: org.bouncycastle:bcprov-ext-jdk14, Maven: org.bouncycastle:bcprov-ext-jdk15to18, Maven: org.bouncycastle:bcprov-ext-jdk18on, Maven: org.bouncycastle:bcprov-ext-debug-jdk14 and 4 more&lt;/p&gt;
&lt;p&gt;The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-574f-3g2m-x479</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10571-1 — bouncycastle-1.84-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10571-1</link>
      <description>&lt;p&gt;bouncycastle-1.84-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bouncycastle-1.84-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10571-1</guid>
    </item>
    <item>
      <title>RHSA-2026:11720 — Red Hat Security Advisory: Red Hat build of Quarkus 3.20.6.SP1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:11720</link>
      <description>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid io.quarkus:quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid io.quarkus:quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:11720</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21404-1 — Security update for bouncycastle</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21404-1</link>
      <description>&lt;p&gt;Security update for bouncycastle&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for bouncycastle&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21404-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-14813</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14813</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: bouncycastle, Ubuntu:Pro:18.04:LTS: bouncycastle, Ubuntu:Pro:20.04:LTS: bouncycastle, Ubuntu:Pro:22.04:LTS: bouncycastle, Ubuntu:Pro:24.04:LTS: bouncycastle, Ubuntu:25.10: bouncycastle, Ubuntu:26.04:LTS: bouncycastle&lt;/p&gt;
&lt;p&gt;: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).  This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: bouncycastle, Ubuntu:Pro:18.04:LTS: bouncycastle, Ubuntu:Pro:20.04:LTS: bouncycastle, Ubuntu:Pro:22.04:LTS: bouncycastle, Ubuntu:Pro:24.04:LTS: bouncycastle, Ubuntu:25.10: bouncycastle, Ubuntu:26.04:LTS: bouncycastle&lt;/p&gt;
&lt;p&gt;: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).  This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14813</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1129 — Bouncy Castle BC-JAVA: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1129</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Bouncy Castle BC-JAVA ausnutzen, um kryptografische Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Bouncy Castle BC-JAVA ausnutzen, um kryptografische Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1129</guid>
    </item>
  </channel>
</rss>
