<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:37:00 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0467 — De multiples vulnérabilités ont été découvertes dans Oracle Database Server. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0467</link>
      <description>certfr-2026-avi-0467</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0467</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-KC30064 — Security fixes in akhq 0.27.1-r5</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-kc30064</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: akhq&lt;/p&gt;
&lt;p&gt;Package akhq version 0.27.1-r5 fixes 27 vulnerabilities: CVE-2026-58062, CVE-2026-59638, CVE-2026-59646, CVE-2026-12802, CVE-2026-59639...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: akhq&lt;/p&gt;
&lt;p&gt;Package akhq version 0.27.1-r5 fixes 27 vulnerabilities: CVE-2026-58062, CVE-2026-59638, CVE-2026-59646, CVE-2026-12802, CVE-2026-59639...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-kc30064</guid>
    </item>
    <item>
      <title>EUVD-2026-277403</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277403</link>
      <description>EUVD-2026-277403</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277403</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33013</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33013</link>
      <description>&lt;p&gt;Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33013</guid>
    </item>
    <item>
      <title>GHSA-43w5-mmxv-cpvh — Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-43w5-mmxv-cpvh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.micronaut:micronaut-json-core&lt;/p&gt;
&lt;p&gt;In `JsonBeanPropertyBinder::expandArrayToThreshold` in `io.micronaut:micronaut-json-core` before Micronaut 4 4.10.16 and in Micronaut 3 before 3.10.5 does not correctly handle descending array index order during form-urlencoded body binding, which allows remote attackers to cause a denial of service (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., `authors[1].name` followed by `authors[0].name`).&lt;/p&gt;
&lt;p&gt;### Example&lt;/p&gt;
&lt;p&gt;With such an application&lt;/p&gt;
&lt;p&gt;```java
package dosform;&lt;/p&gt;
&lt;p&gt;import io.micronaut.http.HttpResponse;
import io.micronaut.http.MediaType;
import io.micronaut.http.annotation.Body;
import io.micronaut.http.annotation.Consumes;
import io.micronaut.http.annotation.Controller;
import io.micronaut.http.annotation.Get;
import io.micronaut.http.annotation.Post;
import io.micronaut.http.annotation.Produces;&lt;/p&gt;
&lt;p&gt;import java.net.URI;&lt;/p&gt;
&lt;p&gt;@Controller
class HomeController {&lt;/p&gt;
&lt;p&gt;@Produces(MediaType.TEXT_HTML)
    @Get
    String index() {
        return &amp;#34;&amp;#34;&amp;#34;
                &amp;lt;!DOCTYPE html&amp;gt;
                &amp;lt;html&amp;gt;
                &amp;lt;head&amp;gt;
                &amp;lt;title&amp;gt;&amp;lt;/title&amp;gt;
                &amp;lt;/head&amp;gt;
                &amp;lt;body&amp;gt;
    &amp;lt;form action=&amp;#34;/submit&amp;#34; method=&amp;#34;post&amp;#34;&amp;gt;
      &amp;lt;label for=&amp;#34;firstAuthor&amp;#34;&amp;gt;Fist Author&amp;lt;/label&amp;gt;
      &amp;lt;input id=&amp;#34;firstAuthor&amp;#34; name=&amp;#34;authors[0].name&amp;#34; type=&amp;#34;text&amp;#34;/&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;label for=&amp;#34;secondAuthor&amp;#34;&amp;gt;Second Author&amp;lt;/label&amp;gt;
      &amp;lt;input id=&amp;#34;secondAuthor&amp;#34; name=&amp;#34;authors[1].name&amp;#34; type=&amp;#34;text&amp;#34;/&amp;gt;
      
      &amp;lt;label for=&amp;#34;thirdAuthor&amp;#34;&amp;gt;Third Author&amp;lt;/lab…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.micronaut:micronaut-json-core&lt;/p&gt;
&lt;p&gt;In `JsonBeanPropertyBinder::expandArrayToThreshold` in `io.micronaut:micronaut-json-core` before Micronaut 4 4.10.16 and in Micronaut 3 before 3.10.5 does not correctly handle descending array index order during form-urlencoded body binding, which allows remote attackers to cause a denial of service (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., `authors[1].name` followed by `authors[0].name`).&lt;/p&gt;
&lt;p&gt;### Example&lt;/p&gt;
&lt;p&gt;With such an application&lt;/p&gt;
&lt;p&gt;```java
package dosform;&lt;/p&gt;
&lt;p&gt;import io.micronaut.http.HttpResponse;
import io.micronaut.http.MediaType;
import io.micronaut.http.annotation.Body;
import io.micronaut.http.annotation.Consumes;
import io.micronaut.http.annotation.Controller;
import io.micronaut.http.annotation.Get;
import io.micronaut.http.annotation.Post;
import io.micronaut.http.annotation.Produces;&lt;/p&gt;
&lt;p&gt;import java.net.URI;&lt;/p&gt;
&lt;p&gt;@Controller
class HomeController {&lt;/p&gt;
&lt;p&gt;@Produces(MediaType.TEXT_HTML)
    @Get
    String index() {
        return &amp;#34;&amp;#34;&amp;#34;
                &amp;lt;!DOCTYPE html&amp;gt;
                &amp;lt;html&amp;gt;
                &amp;lt;head&amp;gt;
                &amp;lt;title&amp;gt;&amp;lt;/title&amp;gt;
                &amp;lt;/head&amp;gt;
                &amp;lt;body&amp;gt;
    &amp;lt;form action=&amp;#34;/submit&amp;#34; method=&amp;#34;post&amp;#34;&amp;gt;
      &amp;lt;label for=&amp;#34;firstAuthor&amp;#34;&amp;gt;Fist Author&amp;lt;/label&amp;gt;
      &amp;lt;input id=&amp;#34;firstAuthor&amp;#34; name=&amp;#34;authors[0].name&amp;#34; type=&amp;#34;text&amp;#34;/&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;label for=&amp;#34;secondAuthor&amp;#34;&amp;gt;Second Author&amp;lt;/label&amp;gt;
      &amp;lt;input id=&amp;#34;secondAuthor&amp;#34; name=&amp;#34;authors[1].name&amp;#34; type=&amp;#34;text&amp;#34;/&amp;gt;
      
      &amp;lt;label for=&amp;#34;thirdAuthor&amp;#34;&amp;gt;Third Author&amp;lt;/lab…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-43w5-mmxv-cpvh</guid>
    </item>
  </channel>
</rss>
