<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:05:52 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AM39668 — yawkat LZ4 Java provides LZ4 compression for Java</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</guid>
    </item>
    <item>
      <title>EUVD-2026-323360</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323360</link>
      <description>EUVD-2026-323360</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323360</guid>
    </item>
    <item>
      <title>fkie_cve-2026-10532</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10532</link>
      <description>&lt;p&gt;Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.&lt;/p&gt;
&lt;p&gt;More precisely, an attacker able to influence serialized data sent to 
SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.&lt;/p&gt;
&lt;p&gt;Although deserialization is heavily restricted by HardenedObjectInputStream and no 
practical way to achieve remote code execution or significant privilege 
escalation has been identified, this issue constitutes a bypass of the 
intended security restrictions.&lt;/p&gt;
&lt;p&gt;This issue affects logback: through 1.5.33 inclusive.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.&lt;/p&gt;
&lt;p&gt;More precisely, an attacker able to influence serialized data sent to 
SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.&lt;/p&gt;
&lt;p&gt;Although deserialization is heavily restricted by HardenedObjectInputStream and no 
practical way to achieve remote code execution or significant privilege 
escalation has been identified, this issue constitutes a bypass of the 
intended security restrictions.&lt;/p&gt;
&lt;p&gt;This issue affects logback: through 1.5.33 inclusive.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-10532</guid>
    </item>
    <item>
      <title>GHSA-jhq6-gfmj-v8fx — Logback vulnerable to Object Injection through HardenedObjectInputStream modules</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jhq6-gfmj-v8fx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: ch.qos.logback:logback-core&lt;/p&gt;
&lt;p&gt;Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.&lt;/p&gt;
&lt;p&gt;More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.&lt;/p&gt;
&lt;p&gt;Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege  escalation has been identified, this issue constitutes a bypass of the  intended security restrictions.&lt;/p&gt;
&lt;p&gt;This issue affects logback: through 1.5.33 inclusive.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: ch.qos.logback:logback-core&lt;/p&gt;
&lt;p&gt;Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.&lt;/p&gt;
&lt;p&gt;More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.&lt;/p&gt;
&lt;p&gt;Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege  escalation has been identified, this issue constitutes a bypass of the  intended security restrictions.&lt;/p&gt;
&lt;p&gt;This issue affects logback: through 1.5.33 inclusive.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jhq6-gfmj-v8fx</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10999-1 — logback-1.5.34-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10999-1</link>
      <description>&lt;p&gt;logback-1.5.34-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;logback-1.5.34-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10999-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-10532</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10532</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:Pro:22.04:LTS: logback, Ubuntu:24.04:LTS: logback, Ubuntu:25.10: logback, Ubuntu:26.04:LTS: logback&lt;/p&gt;
&lt;p&gt;Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects. Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions. This issue affects logback: through 1.5.33 inclusive.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:Pro:22.04:LTS: logback, Ubuntu:24.04:LTS: logback, Ubuntu:25.10: logback, Ubuntu:26.04:LTS: logback&lt;/p&gt;
&lt;p&gt;Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects. Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions. This issue affects logback: through 1.5.33 inclusive.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10532</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2242 — IBM Operational Decision Manager: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2242</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Operational Decision Manager ausnutzen, um Sicherheitsbeschränkungen zu umgehen, um einen Denial of Service zu verursachen und Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Operational Decision Manager ausnutzen, um Sicherheitsbeschränkungen zu umgehen, um einen Denial of Service zu verursachen und Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2242</guid>
    </item>
  </channel>
</rss>
