<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 22:21:11 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-03281</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-03281</link>
      <description>bdu:2025-03281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-03281</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-23419</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-23419</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: nginx, Alpaquita:stream: nginx&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: nginx, Alpaquita:stream: nginx&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-23419</guid>
    </item>
    <item>
      <title>BIT-nginx-2025-23419 — TLS Session Resumption Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/bit-nginx-2025-23419</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: nginx&lt;/p&gt;
&lt;p&gt;When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.&lt;/p&gt;
&lt;p&gt;Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: nginx&lt;/p&gt;
&lt;p&gt;When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.&lt;/p&gt;
&lt;p&gt;Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-nginx-2025-23419</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0099 — De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0099</link>
      <description>certfr-2025-avi-0099</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0099</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AF45008 — When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumptio…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-af45008</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nginx&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the nginx package. When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: nginx&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the nginx package. When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-af45008</guid>
    </item>
    <item>
      <title>EUVD-2026-266504</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266504</link>
      <description>EUVD-2026-266504</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266504</guid>
    </item>
    <item>
      <title>fkie_cve-2025-23419</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-23419</link>
      <description>&lt;p&gt;When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.&lt;/p&gt;
&lt;p&gt;Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.&lt;/p&gt;
&lt;p&gt;Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-23419</guid>
    </item>
    <item>
      <title>GHSA-84xh-pwc6-7g4g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-84xh-pwc6-7g4g</link>
      <description>&lt;p&gt;When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.&lt;/p&gt;
&lt;p&gt;Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.&lt;/p&gt;
&lt;p&gt;Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-84xh-pwc6-7g4g</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-23419 — TLS Session Resumption Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-23419</link>
      <description>msrc_CVE-2025-23419</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-23419</guid>
    </item>
    <item>
      <title>OESA-2025-1134 — nginx security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1134</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: nginx, openEuler:24.03-LTS-SP1: nginx, openEuler:20.03-LTS-SP4: nginx, openEuler:22.03-LTS-SP3: nginx, openEuler:22.03-LTS-SP4: nginx&lt;/p&gt;
&lt;p&gt;NGINX is a free, open-source, high-performance HTTP server and reverse proxy,  as well as an IMAP/POP3 proxy server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.&lt;/p&gt;
&lt;p&gt;Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2025-23419)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: nginx, openEuler:24.03-LTS-SP1: nginx, openEuler:20.03-LTS-SP4: nginx, openEuler:22.03-LTS-SP3: nginx, openEuler:22.03-LTS-SP4: nginx&lt;/p&gt;
&lt;p&gt;NGINX is a free, open-source, high-performance HTTP server and reverse proxy,  as well as an IMAP/POP3 proxy server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.&lt;/p&gt;
&lt;p&gt;Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2025-23419)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1134</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14737-1 — nginx-1.27.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14737-1</link>
      <description>&lt;p&gt;nginx-1.27.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nginx-1.27.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14737-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-23419</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23419</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nginx, Ubuntu:Pro:16.04:LTS: nginx, Ubuntu:Pro:18.04:LTS: nginx, Ubuntu:20.04:LTS: nginx, Ubuntu:22.04:LTS: nginx, Ubuntu:24.04:LTS: nginx&lt;/p&gt;
&lt;p&gt;When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nginx, Ubuntu:Pro:16.04:LTS: nginx, Ubuntu:Pro:18.04:LTS: nginx, Ubuntu:20.04:LTS: nginx, Ubuntu:22.04:LTS: nginx, Ubuntu:24.04:LTS: nginx&lt;/p&gt;
&lt;p&gt;When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23419</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0274 — NGINX: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0274</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in NGINX NGINX Plus und NGINX ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in NGINX NGINX Plus und NGINX ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0274</guid>
    </item>
  </channel>
</rss>
