<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:22:35 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0934 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0934</link>
      <description>certfr-2026-avi-0934</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0934</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AF22825 — Security fix for CVE-2026-47838 applied in: apache-nifi 2.6.0-r3, rundeck 6.0.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-af22825</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi, CleanStart: rundeck&lt;/p&gt;
&lt;p&gt;CVE-2026-47838 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi, CleanStart: rundeck&lt;/p&gt;
&lt;p&gt;CVE-2026-47838 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-af22825</guid>
    </item>
    <item>
      <title>EUVD-2026-331450</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331450</link>
      <description>EUVD-2026-331450</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331450</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47838</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47838</link>
      <description>&lt;p&gt;SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.&lt;/p&gt;
&lt;p&gt;Affected versions:
Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.&lt;/p&gt;
&lt;p&gt;Affected versions:
Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47838</guid>
    </item>
    <item>
      <title>GHSA-293q-567p-wmwq — Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-293q-567p-wmwq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.security:spring-security-web&lt;/p&gt;
&lt;p&gt;In Spring Security Web, `SubjectDnX509PrincipalExtractor` does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.&lt;/p&gt;
&lt;p&gt;`SubjectDnX509PrincipalExtractor` is deprecated by this CVE and replaced with `SubjectX500PrincipalExtractor`. As part of updating, you should also migrate to `SubjectX500PrincipalExtractor`.&lt;/p&gt;
&lt;p&gt;Affected versions:
Spring Security Enterprise 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10. 
OSS 6.5.0 through 6.5.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.security:spring-security-web&lt;/p&gt;
&lt;p&gt;In Spring Security Web, `SubjectDnX509PrincipalExtractor` does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.&lt;/p&gt;
&lt;p&gt;`SubjectDnX509PrincipalExtractor` is deprecated by this CVE and replaced with `SubjectX500PrincipalExtractor`. As part of updating, you should also migrate to `SubjectX500PrincipalExtractor`.&lt;/p&gt;
&lt;p&gt;Affected versions:
Spring Security Enterprise 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10. 
OSS 6.5.0 through 6.5.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-293q-567p-wmwq</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1869 — VMware Tanzu Spring Security: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1869</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Security ausnutzen, um einen Denial of Service zu verursachen, beliebigen Code auszuführen, Benutzer auf beliebige Websites umzuleiten, Informationen offenzulegen und die Identität eines anderen Benutzers anzunehmen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in VMware Tanzu Spring Security ausnutzen, um einen Denial of Service zu verursachen, beliebigen Code auszuführen, Benutzer auf beliebige Websites umzuleiten, Informationen offenzulegen und die Identität eines anderen Benutzers anzunehmen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1869</guid>
    </item>
  </channel>
</rss>
