<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:27:46 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-03480</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-03480</link>
      <description>bdu:2026-03480</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-03480</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0323 — De multiples vulnérabilités ont été découvertes dans les produits Spring. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0323</link>
      <description>certfr-2026-avi-0323</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0323</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AQ60759 — When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibilit…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aq60759</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the apache-nifi package. When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the apache-nifi package. When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aq60759</guid>
    </item>
    <item>
      <title>EUVD-2026-278643</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278643</link>
      <description>EUVD-2026-278643</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278643</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22732</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22732</link>
      <description>&lt;p&gt;When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. 
This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers:&lt;/p&gt;
&lt;p&gt;: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. 
This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers:&lt;/p&gt;
&lt;p&gt;: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22732</guid>
    </item>
    <item>
      <title>GHSA-mf92-479x-3373 — Spring Security HTTP Headers Are not Written Under Some Conditions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mf92-479x-3373</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.security:spring-security-web&lt;/p&gt;
&lt;p&gt;When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. 
This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.security:spring-security-web&lt;/p&gt;
&lt;p&gt;When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. 
This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mf92-479x-3373</guid>
    </item>
    <item>
      <title>NCSC-2026-0258 — Kwetsbaarheden verholpen in Oracle Financial Services</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0258</link>
      <description>NCSC-2026-0258</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0258</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0797 — VMware Tanzu Spring Security: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0797</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Security ausnutzen, um Sicherheitsvorkehrungen zu umgehen und möglicherweise weitere Angriffe durchzuführen, beispielsweise zur Offenlegung vertraulicher Informationen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Security ausnutzen, um Sicherheitsvorkehrungen zu umgehen und möglicherweise weitere Angriffe durchzuführen, beispielsweise zur Offenlegung vertraulicher Informationen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0797</guid>
    </item>
  </channel>
</rss>
