<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:33:47 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:40895 — Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base secur…</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:40895</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: pki-jackson-annotations, AlmaLinux:9: pki-jackson-core, AlmaLinux:9: pki-jackson-databind, AlmaLinux:9: pki-jackson-jaxrs-json-provider, AlmaLinux:9: pki-jackson-jaxrs-providers, AlmaLinux:9: pki-jackson-module-jaxb-annotations&lt;/p&gt;
&lt;p&gt;The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)
  * jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: pki-jackson-annotations, AlmaLinux:9: pki-jackson-core, AlmaLinux:9: pki-jackson-databind, AlmaLinux:9: pki-jackson-jaxrs-json-provider, AlmaLinux:9: pki-jackson-jaxrs-providers, AlmaLinux:9: pki-jackson-module-jaxb-annotations&lt;/p&gt;
&lt;p&gt;The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)
  * jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:40895</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0914 — De multiples vulnérabilités ont été découvertes dans Oracle Database Server. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0914</link>
      <description>certfr-2026-avi-0914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0914</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AM39668 — yawkat LZ4 Java provides LZ4 compression for Java</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</guid>
    </item>
    <item>
      <title>EUVD-2026-329884</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329884</link>
      <description>EUVD-2026-329884</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329884</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54512</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54512</link>
      <description>&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind&amp;#39;s PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains &amp;lt;), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before &amp;lt;) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList&amp;lt;com.evil.Gadget&amp;gt; when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind&amp;#39;s PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains &amp;lt;), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before &amp;lt;) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList&amp;lt;com.evil.Gadget&amp;gt; when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54512</guid>
    </item>
    <item>
      <title>GHSA-j3rv-43j4-c7qm — jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instanti…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j3rv-43j4-c7qm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.jackson.core:jackson-databind, Maven: tools.jackson.core:jackson-databind&lt;/p&gt;
&lt;p&gt;`jackson-databind`&amp;#39;s `PolymorphicTypeValidator` (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains `&amp;lt;`), `DatabindContext._resolveAndValidateGeneric()` validates **only the raw container class name** (the substring before `&amp;lt;`) against the configured PTV.&lt;/p&gt;
&lt;p&gt;If the container type is approved, the method parses the full canonical type string via `TypeFactory.constructFromCanonical()` and returns the fully parameterized type **without ever validating the nested type arguments** against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization.&lt;/p&gt;
&lt;p&gt;An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example `java.util.ArrayList&amp;lt;com.evil.Gadget&amp;gt;` when only `java.util.ArrayList` is allow-listed. The container passes the PTV check; `com.evil.Gadget` is loaded via `Class.forName(name, true, loader)`, instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list.&lt;/p&gt;
&lt;p&gt;This is the same vulnerability class responsible for the historical sequence of jackson-databind deserialization CVEs; here it manifests as a validator bypass rather than a missing deny-list entry.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- **Bypass of the PTV allow-list**, including the recommended `BasicPoly…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.jackson.core:jackson-databind, Maven: tools.jackson.core:jackson-databind&lt;/p&gt;
&lt;p&gt;`jackson-databind`&amp;#39;s `PolymorphicTypeValidator` (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains `&amp;lt;`), `DatabindContext._resolveAndValidateGeneric()` validates **only the raw container class name** (the substring before `&amp;lt;`) against the configured PTV.&lt;/p&gt;
&lt;p&gt;If the container type is approved, the method parses the full canonical type string via `TypeFactory.constructFromCanonical()` and returns the fully parameterized type **without ever validating the nested type arguments** against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization.&lt;/p&gt;
&lt;p&gt;An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example `java.util.ArrayList&amp;lt;com.evil.Gadget&amp;gt;` when only `java.util.ArrayList` is allow-listed. The container passes the PTV check; `com.evil.Gadget` is loaded via `Class.forName(name, true, loader)`, instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list.&lt;/p&gt;
&lt;p&gt;This is the same vulnerability class responsible for the historical sequence of jackson-databind deserialization CVEs; here it manifests as a validator bypass rather than a missing deny-list entry.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- **Bypass of the PTV allow-list**, including the recommended `BasicPoly…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j3rv-43j4-c7qm</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11132-1 — jackson-databind-2.18.8-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11132-1</link>
      <description>&lt;p&gt;jackson-databind-2.18.8-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind-2.18.8-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11132-1</guid>
    </item>
    <item>
      <title>RHSA-2026:41951 — Red Hat Security Advisory: Red Hat Data Grid 8.6.2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:41951</link>
      <description>&lt;p&gt;fast-uri: fast-uri: URI authority bypass due to improper delimiter handling webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration form-data: form-data: Form field override via CRLF injection react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode axios: Axios: Prototype pollution allows information disclosure and request manipulation react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 he…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri: fast-uri: URI authority bypass due to improper delimiter handling webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration form-data: form-data: Form field override via CRLF injection react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode axios: Axios: Prototype pollution allows information disclosure and request manipulation react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 he…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:41951</guid>
    </item>
    <item>
      <title>RLSA-2026:40895 — Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base secur…</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:40895</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: jackson-annotations, Rocky Linux:9: jackson-core, Rocky Linux:9: jackson-databind, Rocky Linux:9: jackson-jaxrs-providers, Rocky Linux:9: jackson-modules-base&lt;/p&gt;
&lt;p&gt;The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)&lt;/p&gt;
&lt;p&gt;* jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: jackson-annotations, Rocky Linux:9: jackson-core, Rocky Linux:9: jackson-databind, Rocky Linux:9: jackson-jaxrs-providers, Rocky Linux:9: jackson-modules-base&lt;/p&gt;
&lt;p&gt;The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)&lt;/p&gt;
&lt;p&gt;* jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:40895</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22504-1 — Security update for jackson-annotations, jackson-core, jackson-databind</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22504-1</link>
      <description>&lt;p&gt;Security update for jackson-annotations, jackson-core, jackson-databind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jackson-annotations, jackson-core, jackson-databind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22504-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54512</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54512</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jackson-databind, Ubuntu:Pro:16.04:LTS: jackson-databind, Ubuntu:18.04:LTS: jackson-databind, Ubuntu:20.04:LTS: jackson-databind, Ubuntu:22.04:LTS: jackson-databind, Ubuntu:24.04:LTS: jackson-databind, Ubuntu:25.10: jackson-databind, Ubuntu:26.04:LTS: jackson-databind&lt;/p&gt;
&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind&amp;#39;s PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains &amp;lt;), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before &amp;lt;) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList&amp;lt;com.evil.Gadget&amp;gt; when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jackson-databind, Ubuntu:Pro:16.04:LTS: jackson-databind, Ubuntu:18.04:LTS: jackson-databind, Ubuntu:20.04:LTS: jackson-databind, Ubuntu:22.04:LTS: jackson-databind, Ubuntu:24.04:LTS: jackson-databind, Ubuntu:25.10: jackson-databind, Ubuntu:26.04:LTS: jackson-databind&lt;/p&gt;
&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind&amp;#39;s PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains &amp;lt;), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before &amp;lt;) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList&amp;lt;com.evil.Gadget&amp;gt; when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54512</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2058 — FasterXML Jackson: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2058</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FasterXML Jackson ausnutzen, um  Schutzmechanismen und Autorisierungsregeln zu umgehen, Daten zu manipulieren, Informationen offenzulegen oder einen Denial-of-Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FasterXML Jackson ausnutzen, um  Schutzmechanismen und Autorisierungsregeln zu umgehen, Daten zu manipulieren, Informationen offenzulegen oder einen Denial-of-Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2058</guid>
    </item>
  </channel>
</rss>
