<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:02:19 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0323 — De multiples vulnérabilités ont été découvertes dans les produits Spring. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0323</link>
      <description>certfr-2026-avi-0323</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0323</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BV41278 — Security fixes in kafka-ui 1.3.0-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bv41278</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kafka-ui&lt;/p&gt;
&lt;p&gt;Package kafka-ui version 1.3.0-r2 fixes 13 vulnerabilities: ghsa-w9fj-cfpg-grvv, ghsa-4773-3jfm-qmx3, ghsa-pwqr-wmgm-9rr8, ghsa-mf92-479x-3373, ghsa-6hcq-hmm3-jj3c...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kafka-ui&lt;/p&gt;
&lt;p&gt;Package kafka-ui version 1.3.0-r2 fixes 13 vulnerabilities: ghsa-w9fj-cfpg-grvv, ghsa-4773-3jfm-qmx3, ghsa-pwqr-wmgm-9rr8, ghsa-mf92-479x-3373, ghsa-6hcq-hmm3-jj3c...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bv41278</guid>
    </item>
    <item>
      <title>EUVD-2026-276652</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276652</link>
      <description>EUVD-2026-276652</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276652</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22737</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22737</link>
      <description>&lt;p&gt;Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22737</guid>
    </item>
    <item>
      <title>GHSA-4773-3jfm-qmx3 — Spring Framework Improper Path Limitation with Script View Templates</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4773-3jfm-qmx3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-webmvc, Maven: org.springframework:spring-webflux&lt;/p&gt;
&lt;p&gt;Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-webmvc, Maven: org.springframework:spring-webflux&lt;/p&gt;
&lt;p&gt;Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4773-3jfm-qmx3</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-22737</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22737</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libspring-java, Ubuntu:Pro:16.04:LTS: libspring-java, Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java, Ubuntu:26.04:LTS: libspring-java&lt;/p&gt;
&lt;p&gt;Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22737</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0796 — VMware Tanzu Spring Framework (MVC and WebFlux): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0796</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Framework ausnutzen, um Dateien zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Framework ausnutzen, um Dateien zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0796</guid>
    </item>
  </channel>
</rss>
