<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:29:53 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-08956</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08956</link>
      <description>bdu:2025-08956</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08956</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</link>
      <description>certfr-2025-avi-0622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AX62295 — Security fixes in solr 9.8.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ax62295</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: solr&lt;/p&gt;
&lt;p&gt;Package solr version 9.8.0-r0 fixes 5 vulnerabilities: ghsa-72hv-8253-57qq, ghsa-j288-q9x7-2f5v, CVE-2025-48924, ghsa-7p63-w6x9-6gr7, CVE-2025-12383&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: solr&lt;/p&gt;
&lt;p&gt;Package solr version 9.8.0-r0 fixes 5 vulnerabilities: ghsa-72hv-8253-57qq, ghsa-j288-q9x7-2f5v, CVE-2025-48924, ghsa-7p63-w6x9-6gr7, CVE-2025-12383&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ax62295</guid>
    </item>
    <item>
      <title>EUVD-2026-260144</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260144</link>
      <description>EUVD-2026-260144</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260144</guid>
    </item>
    <item>
      <title>fkie_cve-2025-48924</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48924</link>
      <description>&lt;p&gt;Uncontrolled Recursion vulnerability in Apache Commons Lang.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.&lt;/p&gt;
&lt;p&gt;The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a 
StackOverflowError could cause an application to stop.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.18.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Uncontrolled Recursion vulnerability in Apache Commons Lang.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.&lt;/p&gt;
&lt;p&gt;The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a 
StackOverflowError could cause an application to stop.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.18.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-48924</guid>
    </item>
    <item>
      <title>GHSA-j288-q9x7-2f5v — Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j288-q9x7-2f5v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.commons:commons-lang3, Maven: commons-lang:commons-lang&lt;/p&gt;
&lt;p&gt;Uncontrolled Recursion vulnerability in Apache Commons Lang.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.&lt;/p&gt;
&lt;p&gt;The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.18.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.commons:commons-lang3, Maven: commons-lang:commons-lang&lt;/p&gt;
&lt;p&gt;Uncontrolled Recursion vulnerability in Apache Commons Lang.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.&lt;/p&gt;
&lt;p&gt;The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.18.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j288-q9x7-2f5v</guid>
    </item>
    <item>
      <title>jvndb-2026-020740</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-020740</link>
      <description>&lt;p&gt;Hitachi Infrastructure Analytics Advisor contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer contains the following vulnerabilities:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer viewpoint contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Viewpoint contains the following vulnerabilities:&#13;
&#13;
CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, CVE-2025-58056, CVE-2025-58057&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hitachi Infrastructure Analytics Advisor contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer contains the following vulnerabilities:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Analyzer viewpoint contains the following vulnerability:&#13;
&#13;
CVE-2025-48924&#13;
&#13;
Hitachi Ops Center Viewpoint contains the following vulnerabilities:&#13;
&#13;
CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, CVE-2025-58056, CVE-2025-58057&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-020740</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-48924 — Apache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-48924</link>
      <description>msrc_CVE-2025-48924</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-48924</guid>
    </item>
    <item>
      <title>NCSC-2026-0020 — Kwetsbaarheden verholpen in Oracle Commerce</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0020</link>
      <description>NCSC-2026-0020</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0020</guid>
    </item>
    <item>
      <title>OESA-2025-1929 — apache-commons-lang3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1929</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: apache-commons-lang3, openEuler:22.03-LTS-SP3: apache-commons-lang3, openEuler:22.03-LTS-SP4: apache-commons-lang3, openEuler:24.03-LTS: apache-commons-lang3, openEuler:24.03-LTS-SP1: apache-commons-lang3, openEuler:24.03-LTS-SP2: apache-commons-lang3&lt;/p&gt;
&lt;p&gt;The standard Java libraries fail to provide enough methods for manipulation of its core classes. The Commons Lang Component provides these extra methods. Lang provides a host of helper utilities for the java.lang API, notably String manipulation methods, basic numerical methods, object reflection, concurrency, creation and serialization and System properties. Additionally it contains basic enhancements to java.util.Date and a series of utilities dedicated to help with building methods, such as hashCode, toString and equals. Note that Lang 3.0 (and subsequent versions) use a different package (org.apache.commons.lang3) than the previous versions (org.apache.commons.lang), allowing it to be used at the same time as an earlier version.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability classified as problematic has been found in Apache Commons Lang up to 2.6/3.17.x.CWE is classifying the issue as CWE-674. The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.This is going to have an impact on confidentiality, integrity, and availability.Upgrading to version 3.18.0 eliminates this vulnerability.(CVE-2025-48924)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: apache-commons-lang3, openEuler:22.03-LTS-SP3: apache-commons-lang3, openEuler:22.03-LTS-SP4: apache-commons-lang3, openEuler:24.03-LTS: apache-commons-lang3, openEuler:24.03-LTS-SP1: apache-commons-lang3, openEuler:24.03-LTS-SP2: apache-commons-lang3&lt;/p&gt;
&lt;p&gt;The standard Java libraries fail to provide enough methods for manipulation of its core classes. The Commons Lang Component provides these extra methods. Lang provides a host of helper utilities for the java.lang API, notably String manipulation methods, basic numerical methods, object reflection, concurrency, creation and serialization and System properties. Additionally it contains basic enhancements to java.util.Date and a series of utilities dedicated to help with building methods, such as hashCode, toString and equals. Note that Lang 3.0 (and subsequent versions) use a different package (org.apache.commons.lang3) than the previous versions (org.apache.commons.lang), allowing it to be used at the same time as an earlier version.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability classified as problematic has been found in Apache Commons Lang up to 2.6/3.17.x.CWE is classifying the issue as CWE-674. The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.This is going to have an impact on confidentiality, integrity, and availability.Upgrading to version 3.18.0 eliminates this vulnerability.(CVE-2025-48924)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1929</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15347-1 — apache-commons-lang3-3.18.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15347-1</link>
      <description>&lt;p&gt;apache-commons-lang3-3.18.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache-commons-lang3-3.18.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15347-1</guid>
    </item>
    <item>
      <title>RHSA-2025:12511 — Red Hat Security Advisory: Streams for Apache Kafka 3.0.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:12511</link>
      <description>&lt;p&gt;json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority jetty-server: Jetty: Gzip Request Body Buffer Corruption kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider netty: Denial of Service attack on windows app using Netty kafka: Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout io.netty:netty-handler: SslHandler doesn&amp;#39;t correctly validate packets which can lead to native crash when using native SSLEngine netty: Denial of Service attack on windows app using Netty commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang io.quarkus/quarkus-vertx: Quarkus potential data leak com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority jetty-server: Jetty: Gzip Request Body Buffer Corruption kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider netty: Denial of Service attack on windows app using Netty kafka: Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout io.netty:netty-handler: SslHandler doesn&amp;#39;t correctly validate packets which can lead to native crash when using native SSLEngine netty: Denial of Service attack on windows app using Netty commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang io.quarkus/quarkus-vertx: Quarkus potential data leak com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:12511</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02786-1 — Security update for apache-commons-lang3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02786-1</link>
      <description>&lt;p&gt;Security update for apache-commons-lang3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache-commons-lang3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02786-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-48924</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48924</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libcommons-lang-java, Ubuntu:Pro:14.04:LTS: libcommons-lang3-java, Ubuntu:Pro:16.04:LTS: libcommons-lang-java, Ubuntu:Pro:16.04:LTS: libcommons-lang3-java, Ubuntu:Pro:18.04:LTS: libcommons-lang-java, Ubuntu:Pro:18.04:LTS: libcommons-lang3-java, Ubuntu:Pro:20.04:LTS: libcommons-lang-java, Ubuntu:Pro:20.04:LTS: libcommons-lang3-java, Ubuntu:22.04:LTS: libcommons-lang-java, Ubuntu:22.04:LTS: libcommons-lang3-java and 3 more&lt;/p&gt;
&lt;p&gt;Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libcommons-lang-java, Ubuntu:Pro:14.04:LTS: libcommons-lang3-java, Ubuntu:Pro:16.04:LTS: libcommons-lang-java, Ubuntu:Pro:16.04:LTS: libcommons-lang3-java, Ubuntu:Pro:18.04:LTS: libcommons-lang-java, Ubuntu:Pro:18.04:LTS: libcommons-lang3-java, Ubuntu:Pro:20.04:LTS: libcommons-lang-java, Ubuntu:Pro:20.04:LTS: libcommons-lang3-java, Ubuntu:22.04:LTS: libcommons-lang-java, Ubuntu:22.04:LTS: libcommons-lang3-java and 3 more&lt;/p&gt;
&lt;p&gt;Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48924</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1540 — Apache Commons Lang: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1540</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Commons Lang ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Commons Lang ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1540</guid>
    </item>
  </channel>
</rss>
