<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:09:20 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0792 — De multiples vulnérabilités ont été découvertes dans les produits Spring. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0792</link>
      <description>certfr-2025-avi-0792</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0792</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-FT93686 — Security fix for CVE-2025-41249 applied in: activemq 5.19.8-r3, activemq 6.1.8-r1, apache-hive 4.0.0-r0, apache-hive 4.…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ft93686</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: activemq, CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;CVE-2025-41249 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: activemq, CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;CVE-2025-41249 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ft93686</guid>
    </item>
    <item>
      <title>EUVD-2026-252828</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-252828</link>
      <description>EUVD-2026-252828</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-252828</guid>
    </item>
    <item>
      <title>fkie_cve-2025-41249</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41249</link>
      <description>&lt;p&gt;The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.&lt;/p&gt;
&lt;p&gt;Your application may be affected by this if you are using Spring Security&amp;#39;s @EnableMethodSecurity feature.&lt;/p&gt;
&lt;p&gt;You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.&lt;/p&gt;
&lt;p&gt;This CVE is published in conjunction with  CVE-2025-41248 https://spring.io/security/cve-2025-41248 .&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.&lt;/p&gt;
&lt;p&gt;Your application may be affected by this if you are using Spring Security&amp;#39;s @EnableMethodSecurity feature.&lt;/p&gt;
&lt;p&gt;You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.&lt;/p&gt;
&lt;p&gt;This CVE is published in conjunction with  CVE-2025-41248 https://spring.io/security/cve-2025-41248 .&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-41249</guid>
    </item>
    <item>
      <title>GHSA-jmp9-x22r-554x — Spring Framework annotation detection mechanism may result in improper authorization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jmp9-x22r-554x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-core&lt;/p&gt;
&lt;p&gt;The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.&lt;/p&gt;
&lt;p&gt;Your application may be affected by this if you are using Spring Security&amp;#39;s @EnableMethodSecurity feature.&lt;/p&gt;
&lt;p&gt;You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.&lt;/p&gt;
&lt;p&gt;This CVE is published in conjunction with  CVE-2025-41248 https://spring.io/security/cve-2025-41248 .&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-core&lt;/p&gt;
&lt;p&gt;The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.&lt;/p&gt;
&lt;p&gt;Your application may be affected by this if you are using Spring Security&amp;#39;s @EnableMethodSecurity feature.&lt;/p&gt;
&lt;p&gt;You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.&lt;/p&gt;
&lt;p&gt;This CVE is published in conjunction with  CVE-2025-41248 https://spring.io/security/cve-2025-41248 .&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jmp9-x22r-554x</guid>
    </item>
    <item>
      <title>jvndb-2026-010299</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-010299</link>
      <description>&lt;p&gt;Multiple vulnerabilities exist in Hitachi Ops Center Common Services.&#13;
&#13;
CVE-2024-4028, CVE-2025-8714, CVE-2025-8715, CVE-2025-10044, CVE-2025-12817, CVE-2025-12818, CVE-2025-41248, CVE-2025-41249&#13;
&#13;
(*)CVE-2026-1190 is removed from the list.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities exist in Hitachi Ops Center Common Services.&#13;
&#13;
CVE-2024-4028, CVE-2025-8714, CVE-2025-8715, CVE-2025-10044, CVE-2025-12817, CVE-2025-12818, CVE-2025-41248, CVE-2025-41249&#13;
&#13;
(*)CVE-2026-1190 is removed from the list.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-010299</guid>
    </item>
    <item>
      <title>NCSC-2026-0020 — Kwetsbaarheden verholpen in Oracle Commerce</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0020</link>
      <description>NCSC-2026-0020</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0020</guid>
    </item>
    <item>
      <title>RHSA-2025:18028 — Red Hat Security Advisory: Red Hat Build of Apache Camel 4.10.7 for Spring Boot release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:18028</link>
      <description>&lt;p&gt;org.eclipse.jgit: XXE vulnerability in Eclipse JGit org.springframework.security/spring-security-core: Spring Security authorization bypass org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions io.minio/minio: minio-java Client XML Tag is Vulnerable to Value Substitution&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;org.eclipse.jgit: XXE vulnerability in Eclipse JGit org.springframework.security/spring-security-core: Spring Security authorization bypass org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions io.minio/minio: minio-java Client XML Tag is Vulnerable to Value Substitution&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:18028</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-41249</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-41249</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security&amp;#39;s @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with  CVE-2025-41248 https://spring.io/security/cve-2025-41248 .&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security&amp;#39;s @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with  CVE-2025-41248 https://spring.io/security/cve-2025-41248 .&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-41249</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2060 — VMware Tanzu Spring Framework und Spring Security: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrung…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2060</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Security und VMware Tanzu Spring Framework ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Security und VMware Tanzu Spring Framework ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2060</guid>
    </item>
  </channel>
</rss>
