<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:59:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-04250</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04250</link>
      <description>bdu:2026-04250</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04250</guid>
    </item>
    <item>
      <title>BIT-jenkins-2026-33001</title>
      <link>https://cve.radiocsirt.org/vuln/bit-jenkins-2026-33001</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: jenkins&lt;/p&gt;
&lt;p&gt;Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: jenkins&lt;/p&gt;
&lt;p&gt;Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-jenkins-2026-33001</guid>
    </item>
    <item>
      <title>EUVD-2026-365481</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-365481</link>
      <description>EUVD-2026-365481</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-365481</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33001</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33001</link>
      <description>&lt;p&gt;Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33001</guid>
    </item>
    <item>
      <title>GHSA-r6qv-frpc-q66c — Jenkins has a link following vulnerability allows arbitrary file creation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r6qv-frpc-q66c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.main:jenkins-core&lt;/p&gt;
&lt;p&gt;Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.main:jenkins-core&lt;/p&gt;
&lt;p&gt;Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r6qv-frpc-q66c</guid>
    </item>
    <item>
      <title>RHSA-2026:10199 — Red Hat Security Advisory: Release of Red Hat OpenShift Developer Tools - Openshift Jenkins 4.21 security update.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10199</link>
      <description>&lt;p&gt;jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression org.jenkins-ci.main/jenkins-core: Jenkins: Stored Cross-site Scripting (XSS) via unescaped user-provided offline cause description org.jenkins-ci.main/jenkins-core: Jenkins: Information disclosure via unauthorized access to build parameters jenkins: Jenkins: Arbitrary file write and potential code execution through crafted archives&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression org.jenkins-ci.main/jenkins-core: Jenkins: Stored Cross-site Scripting (XSS) via unescaped user-provided offline cause description org.jenkins-ci.main/jenkins-core: Jenkins: Information disclosure via unauthorized access to build parameters jenkins: Jenkins: Arbitrary file write and potential code execution through crafted archives&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10199</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0779 — Jenkins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0779</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0779</guid>
    </item>
  </channel>
</rss>
