<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:01:03 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-06805</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06805</link>
      <description>bdu:2025-06805</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06805</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0514 — Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elle permet à un attaquant de provoquer un contournement de la…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0514</link>
      <description>certfr-2025-avi-0514</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0514</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-VY88502 — Security fixes in kogito-apps 10.1.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-vy88502</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kogito-apps&lt;/p&gt;
&lt;p&gt;Package kogito-apps version 10.1.0-r0 fixes 26 vulnerabilities: CVE-2025-55163, ghsa-prj3-ccx8-p6x4, CVE-2025-67735, ghsa-84h7-rjj3-6jx4, CVE-2025-58057...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kogito-apps&lt;/p&gt;
&lt;p&gt;Package kogito-apps version 10.1.0-r0 fixes 26 vulnerabilities: CVE-2025-55163, ghsa-prj3-ccx8-p6x4, CVE-2025-67735, ghsa-84h7-rjj3-6jx4, CVE-2025-58057...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-vy88502</guid>
    </item>
    <item>
      <title>EUVD-2026-243898</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-243898</link>
      <description>EUVD-2026-243898</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-243898</guid>
    </item>
    <item>
      <title>fkie_cve-2025-49146</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49146</link>
      <description>&lt;p&gt;pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-49146</guid>
    </item>
    <item>
      <title>GHSA-hq9p-pm7w-8p54 — pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hq9p-pm7w-8p54</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.postgresql:postgresql&lt;/p&gt;
&lt;p&gt;### Impact
When the PostgreSQL JDBC driver is configured with channel binding set to `required` (default value is `prefer`), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI  authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements.&lt;/p&gt;
&lt;p&gt;### Patches
TBD&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Configure `sslMode=verify-full` to prevent MITM attacks.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://www.postgresql.org/docs/current/sasl-authentication.html#SASL-SCRAM-SHA-256
* https://datatracker.ietf.org/doc/html/rfc7677
* https://datatracker.ietf.org/doc/html/rfc5802&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.postgresql:postgresql&lt;/p&gt;
&lt;p&gt;### Impact
When the PostgreSQL JDBC driver is configured with channel binding set to `required` (default value is `prefer`), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI  authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements.&lt;/p&gt;
&lt;p&gt;### Patches
TBD&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Configure `sslMode=verify-full` to prevent MITM attacks.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://www.postgresql.org/docs/current/sasl-authentication.html#SASL-SCRAM-SHA-256
* https://datatracker.ietf.org/doc/html/rfc7677
* https://datatracker.ietf.org/doc/html/rfc5802&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hq9p-pm7w-8p54</guid>
    </item>
    <item>
      <title>NCSC-2026-0034 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0034</link>
      <description>NCSC-2026-0034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0034</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15264-1 — postgresql-jdbc-42.7.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15264-1</link>
      <description>&lt;p&gt;postgresql-jdbc-42.7.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql-jdbc-42.7.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15264-1</guid>
    </item>
    <item>
      <title>RHSA-2025:10323 — Red Hat Security Advisory: Red Hat build of Cryostat security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:10323</link>
      <description>&lt;p&gt;net/http: Request smuggling due to acceptance of invalid chunked data in net/http pgjdbc: pgjdbc insecure authentication in channel binding&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;net/http: Request smuggling due to acceptance of invalid chunked data in net/http pgjdbc: pgjdbc insecure authentication in channel binding&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:10323</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-49146</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49146</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libpgjava, Ubuntu:16.04:LTS: libpgjava, Ubuntu:Pro:18.04:LTS: libpgjava, Ubuntu:Pro:20.04:LTS: libpgjava, Ubuntu:22.04:LTS: libpgjava, Ubuntu:24.04:LTS: libpgjava, Ubuntu:25.10: libpgjava, Ubuntu:26.04:LTS: libpgjava&lt;/p&gt;
&lt;p&gt;pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libpgjava, Ubuntu:16.04:LTS: libpgjava, Ubuntu:Pro:18.04:LTS: libpgjava, Ubuntu:Pro:20.04:LTS: libpgjava, Ubuntu:22.04:LTS: libpgjava, Ubuntu:24.04:LTS: libpgjava, Ubuntu:25.10: libpgjava, Ubuntu:26.04:LTS: libpgjava&lt;/p&gt;
&lt;p&gt;pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49146</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1328 — PostgreSQL JDBC Treiber: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1328</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle im PostgreSQL JDBC Treiber ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle im PostgreSQL JDBC Treiber ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1328</guid>
    </item>
  </channel>
</rss>
