<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:11:08 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-15579</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15579</link>
      <description>bdu:2025-15579</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15579</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0756 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</link>
      <description>certfr-2025-avi-0756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CU18187 — Security fixes in stargate 1.0.90-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cu18187</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Package stargate version 1.0.90-r4 fixes 87 vulnerabilities: ghsa-76h9-2vwh-w278, ghsa-pqr6-cmr2-h8hf, ghsa-fjpj-2g6w-x25r, ghsa-qcwq-55hx-v3vh, ghsa-55g7-9cwv-5qfv...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stargate&lt;/p&gt;
&lt;p&gt;Package stargate version 1.0.90-r4 fixes 87 vulnerabilities: ghsa-76h9-2vwh-w278, ghsa-pqr6-cmr2-h8hf, ghsa-fjpj-2g6w-x25r, ghsa-qcwq-55hx-v3vh, ghsa-55g7-9cwv-5qfv...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cu18187</guid>
    </item>
    <item>
      <title>EUVD-2026-239156</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-239156</link>
      <description>EUVD-2026-239156</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-239156</guid>
    </item>
    <item>
      <title>fkie_cve-2025-46392</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46392</link>
      <description>&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x.&lt;/p&gt;
&lt;p&gt;There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend to fix these issues in 1.x. Apache Commons Configuration 1.x is still safe to use in scenario&amp;#39;s where you only load trusted configurations.&lt;/p&gt;
&lt;p&gt;Users that load untrusted configurations or give attackers control over usage patterns are recommended to upgrade to the 2.x version line, which fixes these issues. Apache Commons Configuration 2.x is not a drop-in replacement, but as it uses a separate Maven groupId and Java package namespace they can be loaded side-by-side, making it possible to do a gradual migration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x.&lt;/p&gt;
&lt;p&gt;There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend to fix these issues in 1.x. Apache Commons Configuration 1.x is still safe to use in scenario&amp;#39;s where you only load trusted configurations.&lt;/p&gt;
&lt;p&gt;Users that load untrusted configurations or give attackers control over usage patterns are recommended to upgrade to the 2.x version line, which fixes these issues. Apache Commons Configuration 2.x is not a drop-in replacement, but as it uses a separate Maven groupId and Java package namespace they can be loaded side-by-side, making it possible to do a gradual migration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-46392</guid>
    </item>
    <item>
      <title>GHSA-pvp8-3xj6-8c6x — Apache Commons Configuration Uncontrolled Resource Consumption</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pvp8-3xj6-8c6x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: commons-configuration:commons-configuration&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x.&lt;/p&gt;
&lt;p&gt;There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend to fix these issues in 1.x. Apache Commons Configuration 1.x is still safe to use in scenarios where you only load trusted configurations.&lt;/p&gt;
&lt;p&gt;Users that load untrusted configurations or give attackers control over usage patterns are recommended to upgrade to the 2.x version line, which fixes these issues. Apache Commons Configuration 2.x is not a drop-in replacement, but as it uses a separate Maven groupId and Java package namespace they can be loaded side-by-side, making it possible to do a gradual migration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: commons-configuration:commons-configuration&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x.&lt;/p&gt;
&lt;p&gt;There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend to fix these issues in 1.x. Apache Commons Configuration 1.x is still safe to use in scenarios where you only load trusted configurations.&lt;/p&gt;
&lt;p&gt;Users that load untrusted configurations or give attackers control over usage patterns are recommended to upgrade to the 2.x version line, which fixes these issues. Apache Commons Configuration 2.x is not a drop-in replacement, but as it uses a separate Maven groupId and Java package namespace they can be loaded side-by-side, making it possible to do a gradual migration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pvp8-3xj6-8c6x</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-46392</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46392</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: commons-configuration, Ubuntu:16.04:LTS: commons-configuration, Ubuntu:18.04:LTS: commons-configuration, Ubuntu:20.04:LTS: commons-configuration, Ubuntu:22.04:LTS: commons-configuration, Ubuntu:24.04:LTS: commons-configuration, Ubuntu:25.10: commons-configuration, Ubuntu:26.04:LTS: commons-configuration&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend to fix these issues in 1.x. Apache Commons Configuration 1.x is still safe to use in scenario&amp;#39;s where you only load trusted configurations. Users that load untrusted configurations or give attackers control over usage patterns are recommended to upgrade to the 2.x version line, which fixes these issues. Apache Commons Configuration 2.x is not a drop-in replacement, but as it uses a separate Maven groupId and Java package namespace they can be loaded side-by-side, making it possible to do a gradual migration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: commons-configuration, Ubuntu:16.04:LTS: commons-configuration, Ubuntu:18.04:LTS: commons-configuration, Ubuntu:20.04:LTS: commons-configuration, Ubuntu:22.04:LTS: commons-configuration, Ubuntu:24.04:LTS: commons-configuration, Ubuntu:25.10: commons-configuration, Ubuntu:26.04:LTS: commons-configuration&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend to fix these issues in 1.x. Apache Commons Configuration 1.x is still safe to use in scenario&amp;#39;s where you only load trusted configurations. Users that load untrusted configurations or give attackers control over usage patterns are recommended to upgrade to the 2.x version line, which fixes these issues. Apache Commons Configuration 2.x is not a drop-in replacement, but as it uses a separate Maven groupId and Java package namespace they can be loaded side-by-side, making it possible to do a gradual migration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46392</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0997 — Apache Commons Configuration: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0997</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Commons Configuration ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Commons Configuration ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0997</guid>
    </item>
  </channel>
</rss>
