<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:27:09 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0967 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</link>
      <description>certfr-2025-avi-0967</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</guid>
    </item>
    <item>
      <title>EUVD-2026-238336</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-238336</link>
      <description>EUVD-2026-238336</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-238336</guid>
    </item>
    <item>
      <title>fkie_cve-2025-46551</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46551</link>
      <description>&lt;p&gt;JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.0.1), when verifying SSL certificates, JRuby-OpenSSL does not verify that the hostname presented in the certificate matches the one the user tries to connect to. This means a man-in-the-middle could just present any valid cert for a completely different domain they own, and JRuby would accept the cert. Anybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely. JRuby-OpenSSL version 0.15.4 contains a fix for the issue. This fix is included in JRuby versions 10.0.0.1 and 9.4.12.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.0.1), when verifying SSL certificates, JRuby-OpenSSL does not verify that the hostname presented in the certificate matches the one the user tries to connect to. This means a man-in-the-middle could just present any valid cert for a completely different domain they own, and JRuby would accept the cert. Anybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely. JRuby-OpenSSL version 0.15.4 contains a fix for the issue. This fix is included in JRuby versions 10.0.0.1 and 9.4.12.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-46551</guid>
    </item>
    <item>
      <title>GHSA-72qj-48g4-5xgx — JRuby-OpenSSL has hostname verification disabled by default</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-72qj-48g4-5xgx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: rubygems:jruby-openssl, Maven: org.jruby:jruby, RubyGems: jruby-openssl&lt;/p&gt;
&lt;p&gt;### Summary
When verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present _any_ valid cert for a completely different domain they own, and JRuby wouldn&amp;#39;t complain.&lt;/p&gt;
&lt;p&gt;### Details
n/a&lt;/p&gt;
&lt;p&gt;### PoC
An example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with `certificate verify failed (hostname mismatch)`, but will work just fine in JRuby 10.0.0.0 and JRuby 9.4.2.0, both of which use jruby-openssl version 0.15.3&lt;/p&gt;
&lt;p&gt;```ruby
require &amp;#34;net/http&amp;#34;
require &amp;#34;openssl&amp;#34;&lt;/p&gt;
&lt;p&gt;uri   = URI(&amp;#34;https://bad.substitutealert.com/&amp;#34;)
https = Net::HTTP.new(uri.host, uri.port)
https.use_ssl      = true
https.verify_mode  = OpenSSL::SSL::VERIFY_PEER&lt;/p&gt;
&lt;p&gt;body = https.start { https.get(uri.request_uri).body }
puts body
```&lt;/p&gt;
&lt;p&gt;### Impact
Anybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: rubygems:jruby-openssl, Maven: org.jruby:jruby, RubyGems: jruby-openssl&lt;/p&gt;
&lt;p&gt;### Summary
When verifying SSL certificates, jruby-openssl is not verifying that the hostname presented in the certificate matches the one we are trying to connect to, meaning a MITM could just present _any_ valid cert for a completely different domain they own, and JRuby wouldn&amp;#39;t complain.&lt;/p&gt;
&lt;p&gt;### Details
n/a&lt;/p&gt;
&lt;p&gt;### PoC
An example domain bad.substitutealert.com was created to present the a certificate for the domain s8a.me. The following script run in IRB in CRuby 3.4.3 will fail with `certificate verify failed (hostname mismatch)`, but will work just fine in JRuby 10.0.0.0 and JRuby 9.4.2.0, both of which use jruby-openssl version 0.15.3&lt;/p&gt;
&lt;p&gt;```ruby
require &amp;#34;net/http&amp;#34;
require &amp;#34;openssl&amp;#34;&lt;/p&gt;
&lt;p&gt;uri   = URI(&amp;#34;https://bad.substitutealert.com/&amp;#34;)
https = Net::HTTP.new(uri.host, uri.port)
https.use_ssl      = true
https.verify_mode  = OpenSSL::SSL::VERIFY_PEER&lt;/p&gt;
&lt;p&gt;body = https.start { https.get(uri.request_uri).body }
puts body
```&lt;/p&gt;
&lt;p&gt;### Impact
Anybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-72qj-48g4-5xgx</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-46551</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46551</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: jruby-openssl, Ubuntu:18.04:LTS: jruby-openssl, Ubuntu:20.04:LTS: jruby-openssl, Ubuntu:22.04:LTS: jruby-openssl&lt;/p&gt;
&lt;p&gt;JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.0.1), when verifying SSL certificates, JRuby-OpenSSL does not verify that the hostname presented in the certificate matches the one the user tries to connect to. This means a man-in-the-middle could just present any valid cert for a completely different domain they own, and JRuby would accept the cert. Anybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely. JRuby-OpenSSL version 0.15.4 contains a fix for the issue. This fix is included in JRuby versions 10.0.0.1 and 9.4.12.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: jruby-openssl, Ubuntu:18.04:LTS: jruby-openssl, Ubuntu:20.04:LTS: jruby-openssl, Ubuntu:22.04:LTS: jruby-openssl&lt;/p&gt;
&lt;p&gt;JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.0.1), when verifying SSL certificates, JRuby-OpenSSL does not verify that the hostname presented in the certificate matches the one the user tries to connect to. This means a man-in-the-middle could just present any valid cert for a completely different domain they own, and JRuby would accept the cert. Anybody using JRuby to make requests of external APIs, or scraping the web, that depends on https to connect securely. JRuby-OpenSSL version 0.15.4 contains a fix for the issue. This fix is included in JRuby versions 10.0.0.1 and 9.4.12.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46551</guid>
    </item>
  </channel>
</rss>
