<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:04:45 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-DV46415 — Security fixes in apache-hive 4.0.1-r5</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-dv46415</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;Package apache-hive version 4.0.1-r5 fixes 11 vulnerabilities: CVE-2025-41242, CVE-2025-48924, CVE-2026-22745, CVE-2026-40563, CVE-2026-41603...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;Package apache-hive version 4.0.1-r5 fixes 11 vulnerabilities: CVE-2025-41242, CVE-2025-48924, CVE-2026-22745, CVE-2026-40563, CVE-2026-41603...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-dv46415</guid>
    </item>
    <item>
      <title>EUVD-2026-330023</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330023</link>
      <description>EUVD-2026-330023</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330023</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50193</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50193</link>
      <description>&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNode (ObjectMapper.readTree()) and writes out same (or modifided) node using JsonNode.toString(). This can consume significant amount of resources with concurrent relatively small requests (1000 nested arrays is 2kB). This vulnerability is fixed in 2.14.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNode (ObjectMapper.readTree()) and writes out same (or modifided) node using JsonNode.toString(). This can consume significant amount of resources with concurrent relatively small requests (1000 nested arrays is 2kB). This vulnerability is fixed in 2.14.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50193</guid>
    </item>
    <item>
      <title>GHSA-3wrr-7qpf-2prh — jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3wrr-7qpf-2prh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.jackson.core:jackson-databind&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Potential Denial-of-Service when attacker sends deeply nested JSON if (and only if) service:&lt;/p&gt;
&lt;p&gt;1. Reads deeply nested (1000s of levels) JSON as `JsonNode` (ObjectMapper.readTree())
2. Writes out same (or modifided) node using `JsonNode.toString()`&lt;/p&gt;
&lt;p&gt;which can consume significant amount of resources with concurrent relatively small requests (1000 nested arrays is 2kB).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in 2.14.0 via https://github.com/FasterXML/jackson-databind/issues/3447.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Avoid serializing `JsonNode` using `toString()`: use ObjectMapper.writeValueAsString(node)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.jackson.core:jackson-databind&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Potential Denial-of-Service when attacker sends deeply nested JSON if (and only if) service:&lt;/p&gt;
&lt;p&gt;1. Reads deeply nested (1000s of levels) JSON as `JsonNode` (ObjectMapper.readTree())
2. Writes out same (or modifided) node using `JsonNode.toString()`&lt;/p&gt;
&lt;p&gt;which can consume significant amount of resources with concurrent relatively small requests (1000 nested arrays is 2kB).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in 2.14.0 via https://github.com/FasterXML/jackson-databind/issues/3447.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Avoid serializing `JsonNode` using `toString()`: use ObjectMapper.writeValueAsString(node)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3wrr-7qpf-2prh</guid>
    </item>
    <item>
      <title>RHSA-2026:41951 — Red Hat Security Advisory: Red Hat Data Grid 8.6.2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:41951</link>
      <description>&lt;p&gt;fast-uri: fast-uri: URI authority bypass due to improper delimiter handling webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration form-data: form-data: Form field override via CRLF injection react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode axios: Axios: Prototype pollution allows information disclosure and request manipulation react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 he…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri: fast-uri: URI authority bypass due to improper delimiter handling webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration form-data: form-data: Form field override via CRLF injection react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode axios: Axios: Prototype pollution allows information disclosure and request manipulation react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 he…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:41951</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-50193</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50193</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jackson-databind, Ubuntu:Pro:16.04:LTS: jackson-databind, Ubuntu:18.04:LTS: jackson-databind, Ubuntu:20.04:LTS: jackson-databind, Ubuntu:22.04:LTS: jackson-databind, Ubuntu:24.04:LTS: jackson-databind, Ubuntu:25.10: jackson-databind, Ubuntu:26.04:LTS: jackson-databind&lt;/p&gt;
&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNode (ObjectMapper.readTree()) and writes out same (or modifided) node using JsonNode.toString(). This can consume significant amount of resources with concurrent relatively small requests (1000 nested arrays is 2kB). This vulnerability is fixed in 2.14.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jackson-databind, Ubuntu:Pro:16.04:LTS: jackson-databind, Ubuntu:18.04:LTS: jackson-databind, Ubuntu:20.04:LTS: jackson-databind, Ubuntu:22.04:LTS: jackson-databind, Ubuntu:24.04:LTS: jackson-databind, Ubuntu:25.10: jackson-databind, Ubuntu:26.04:LTS: jackson-databind&lt;/p&gt;
&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNode (ObjectMapper.readTree()) and writes out same (or modifided) node using JsonNode.toString(). This can consume significant amount of resources with concurrent relatively small requests (1000 nested arrays is 2kB). This vulnerability is fixed in 2.14.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50193</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2058 — FasterXML Jackson: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2058</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FasterXML Jackson ausnutzen, um  Schutzmechanismen und Autorisierungsregeln zu umgehen, Daten zu manipulieren, Informationen offenzulegen oder einen Denial-of-Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FasterXML Jackson ausnutzen, um  Schutzmechanismen und Autorisierungsregeln zu umgehen, Daten zu manipulieren, Informationen offenzulegen oder einen Denial-of-Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2058</guid>
    </item>
  </channel>
</rss>
