<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:53:45 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05835</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05835</link>
      <description>bdu:2026-05835</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05835</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>EUVD-2026-354853</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-354853</link>
      <description>EUVD-2026-354853</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-354853</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40478</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40478</link>
      <description>&lt;p&gt;Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of unauthorized expressions. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library&amp;#39;s protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of unauthorized expressions. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library&amp;#39;s protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40478</guid>
    </item>
    <item>
      <title>GHSA-xjw8-8c5c-9r79 — Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xjw8-8c5c-9r79</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.thymeleaf:thymeleaf, Maven: org.thymeleaf:thymeleaf-spring5, Maven: org.thymeleaf:thymeleaf-spring6&lt;/p&gt;
&lt;p&gt;### Impact
A security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf up to and including 3.1.3.RELEASE. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of unauthorized expressions. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library&amp;#39;s protections to achieve Server-Side Template Injection (SSTI).&lt;/p&gt;
&lt;p&gt;### Patches
This has been fixed in Thymeleaf 3.1.4.RELEASE.&lt;/p&gt;
&lt;p&gt;### Workarounds
No workaround is available beyond ensuring applications do not pass unvalidated user input directly to the template engine. Upgrading to 3.1.4.RELEASE is strongly recommended in any case.&lt;/p&gt;
&lt;p&gt;### Credits
Thanks to Dawid Bakaj (VIPentest.com) for responsible disclosure.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.thymeleaf:thymeleaf, Maven: org.thymeleaf:thymeleaf-spring5, Maven: org.thymeleaf:thymeleaf-spring6&lt;/p&gt;
&lt;p&gt;### Impact
A security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf up to and including 3.1.3.RELEASE. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of unauthorized expressions. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library&amp;#39;s protections to achieve Server-Side Template Injection (SSTI).&lt;/p&gt;
&lt;p&gt;### Patches
This has been fixed in Thymeleaf 3.1.4.RELEASE.&lt;/p&gt;
&lt;p&gt;### Workarounds
No workaround is available beyond ensuring applications do not pass unvalidated user input directly to the template engine. Upgrading to 3.1.4.RELEASE is strongly recommended in any case.&lt;/p&gt;
&lt;p&gt;### Credits
Thanks to Dawid Bakaj (VIPentest.com) for responsible disclosure.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xjw8-8c5c-9r79</guid>
    </item>
    <item>
      <title>RHSA-2026:21772 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.28.0 Release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:21772</link>
      <description>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter markdown-it: markdown-it: Denial of Service via Regular Expression Denial of Service in linkify function bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions svgo: SVGO: Denial of Service via XML entity expansion express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking tar: tar: File overwrite via drive-relative symlink traversal flatted: flatted: Unbounded recursion DoS in parse() revive phase crypto/x509: crypto/tls: golang: Go: Denial of Service vulnera…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter markdown-it: markdown-it: Denial of Service via Regular Expression Denial of Service in linkify function bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions svgo: SVGO: Denial of Service via XML entity expansion express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking tar: tar: File overwrite via drive-relative symlink traversal flatted: flatted: Unbounded recursion DoS in parse() revive phase crypto/x509: crypto/tls: golang: Go: Denial of Service vulnera…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:21772</guid>
    </item>
  </channel>
</rss>
