<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:34:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-01705</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01705</link>
      <description>bdu:2026-01705</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01705</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</link>
      <description>certfr-2025-avi-0622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</guid>
    </item>
    <item>
      <title>EUVD-2026-254722</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-254722</link>
      <description>EUVD-2026-254722</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-254722</guid>
    </item>
    <item>
      <title>fkie_cve-2025-4949</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4949</link>
      <description>&lt;p&gt;In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-4949</guid>
    </item>
    <item>
      <title>GHSA-vrpq-qp53-qv56 — Eclipse JGit XML External Entity (XXE) Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vrpq-qp53-qv56</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jgit:org.eclipse.jgit&lt;/p&gt;
&lt;p&gt;In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jgit:org.eclipse.jgit&lt;/p&gt;
&lt;p&gt;In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vrpq-qp53-qv56</guid>
    </item>
    <item>
      <title>NCSC-2026-0027 — Kwetsbaarheden verholpen in Oracle Fusion Middleware</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0027</link>
      <description>NCSC-2026-0027</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0027</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15232-1 — jgit-5.11.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15232-1</link>
      <description>&lt;p&gt;jgit-5.11.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jgit-5.11.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15232-1</guid>
    </item>
    <item>
      <title>RHSA-2025:18028 — Red Hat Security Advisory: Red Hat Build of Apache Camel 4.10.7 for Spring Boot release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:18028</link>
      <description>&lt;p&gt;org.eclipse.jgit: XXE vulnerability in Eclipse JGit org.springframework.security/spring-security-core: Spring Security authorization bypass org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions io.minio/minio: minio-java Client XML Tag is Vulnerable to Value Substitution&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;org.eclipse.jgit: XXE vulnerability in Eclipse JGit org.springframework.security/spring-security-core: Spring Security authorization bypass org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions io.minio/minio: minio-java Client XML Tag is Vulnerable to Value Substitution&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:18028</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-4949</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4949</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: jgit, Ubuntu:18.04:LTS: jgit, Ubuntu:20.04:LTS: jgit, Ubuntu:22.04:LTS: jgit, Ubuntu:24.04:LTS: jgit, Ubuntu:25.10: jgit, Ubuntu:26.04:LTS: jgit&lt;/p&gt;
&lt;p&gt;In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: jgit, Ubuntu:18.04:LTS: jgit, Ubuntu:20.04:LTS: jgit, Ubuntu:22.04:LTS: jgit, Ubuntu:24.04:LTS: jgit, Ubuntu:25.10: jgit, Ubuntu:26.04:LTS: jgit&lt;/p&gt;
&lt;p&gt;In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4949</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2160 — IBM App Connect Enterprise: Schwachstelle ermöglicht Offenlegung von Informationen, Denial of Service, und einen nicht…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2160</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, und um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, und um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2160</guid>
    </item>
  </channel>
</rss>
