<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:51:13 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0914 — De multiples vulnérabilités ont été découvertes dans Oracle Database Server. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0914</link>
      <description>certfr-2026-avi-0914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0914</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AM39668 — yawkat LZ4 Java provides LZ4 compression for Java</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</guid>
    </item>
    <item>
      <title>EUVD-2026-330169</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330169</link>
      <description>EUVD-2026-330169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330169</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54514</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54514</link>
      <description>&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54514</guid>
    </item>
    <item>
      <title>GHSA-hgj6-7826-r7m5 — jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hgj6-7826-r7m5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.jackson.core:jackson-databind, Maven: tools.jackson.core:jackson-databind&lt;/p&gt;
&lt;p&gt;## Summary
`JDKFromStringDeserializer` constructed `InetSocketAddress` with `new InetSocketAddress(host, port)`, which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an `InetSocketAddress` field issues an attacker-chosen DNS query during `readValue`, before any application-level validation or connect logic. The fix uses `InetSocketAddress.createUnresolved(host, port)`, deferring DNS to an explicit connect.&lt;/p&gt;
&lt;p&gt;## Impact
An attacker controlling JSON deserialized into an `InetSocketAddress`-bearing type can force outbound DNS lookups for attacker-chosen hostnames at deserialization time (SSRF / DNS-based out-of-band interaction / internal-resolver probing), purely from binding.&lt;/p&gt;
&lt;p&gt;## Affected / Patched (verified via `git tag --contains` on `1f5a103`)
- 2.18 line: `&amp;gt;= 2.18.0, &amp;lt; 2.18.8` -&amp;gt; fixed in **2.18.8**
- 2.19-2.21 line: `&amp;gt;= 2.19.0, &amp;lt; 2.21.4` -&amp;gt; fixed in **2.21.4**
- 3.x line: `&amp;gt;= 3.0.0, &amp;lt; 3.1.4` -&amp;gt; fixed in **3.1.4**&lt;/p&gt;
&lt;p&gt;## Severity / CWE
Maintainer: minor. Reporter: LOW. CWE-918 (SSRF).&lt;/p&gt;
&lt;p&gt;## Upstream fix
FasterXML/jackson-databind#5951 (&amp;#34;Improve InetSocketAddress deserialization&amp;#34;). Released 2026-06-04 in 2.18.8 / 2.21.4 / 3.1.4.&lt;/p&gt;
&lt;p&gt;## Credits
Omkhar Arasaratnam (@omkhar) - finder.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.fasterxml.jackson.core:jackson-databind, Maven: tools.jackson.core:jackson-databind&lt;/p&gt;
&lt;p&gt;## Summary
`JDKFromStringDeserializer` constructed `InetSocketAddress` with `new InetSocketAddress(host, port)`, which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an `InetSocketAddress` field issues an attacker-chosen DNS query during `readValue`, before any application-level validation or connect logic. The fix uses `InetSocketAddress.createUnresolved(host, port)`, deferring DNS to an explicit connect.&lt;/p&gt;
&lt;p&gt;## Impact
An attacker controlling JSON deserialized into an `InetSocketAddress`-bearing type can force outbound DNS lookups for attacker-chosen hostnames at deserialization time (SSRF / DNS-based out-of-band interaction / internal-resolver probing), purely from binding.&lt;/p&gt;
&lt;p&gt;## Affected / Patched (verified via `git tag --contains` on `1f5a103`)
- 2.18 line: `&amp;gt;= 2.18.0, &amp;lt; 2.18.8` -&amp;gt; fixed in **2.18.8**
- 2.19-2.21 line: `&amp;gt;= 2.19.0, &amp;lt; 2.21.4` -&amp;gt; fixed in **2.21.4**
- 3.x line: `&amp;gt;= 3.0.0, &amp;lt; 3.1.4` -&amp;gt; fixed in **3.1.4**&lt;/p&gt;
&lt;p&gt;## Severity / CWE
Maintainer: minor. Reporter: LOW. CWE-918 (SSRF).&lt;/p&gt;
&lt;p&gt;## Upstream fix
FasterXML/jackson-databind#5951 (&amp;#34;Improve InetSocketAddress deserialization&amp;#34;). Released 2026-06-04 in 2.18.8 / 2.21.4 / 3.1.4.&lt;/p&gt;
&lt;p&gt;## Credits
Omkhar Arasaratnam (@omkhar) - finder.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hgj6-7826-r7m5</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11118-1 — jackson-databind-2.18.8-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11118-1</link>
      <description>&lt;p&gt;jackson-databind-2.18.8-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind-2.18.8-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11118-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22504-1 — Security update for jackson-annotations, jackson-core, jackson-databind</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22504-1</link>
      <description>&lt;p&gt;Security update for jackson-annotations, jackson-core, jackson-databind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jackson-annotations, jackson-core, jackson-databind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22504-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54514</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54514</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jackson-databind, Ubuntu:Pro:16.04:LTS: jackson-databind, Ubuntu:18.04:LTS: jackson-databind, Ubuntu:20.04:LTS: jackson-databind, Ubuntu:22.04:LTS: jackson-databind, Ubuntu:24.04:LTS: jackson-databind, Ubuntu:25.10: jackson-databind, Ubuntu:26.04:LTS: jackson-databind&lt;/p&gt;
&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jackson-databind, Ubuntu:Pro:16.04:LTS: jackson-databind, Ubuntu:18.04:LTS: jackson-databind, Ubuntu:20.04:LTS: jackson-databind, Ubuntu:22.04:LTS: jackson-databind, Ubuntu:24.04:LTS: jackson-databind, Ubuntu:25.10: jackson-databind, Ubuntu:26.04:LTS: jackson-databind&lt;/p&gt;
&lt;p&gt;jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54514</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2058 — FasterXML Jackson: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2058</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FasterXML Jackson ausnutzen, um  Schutzmechanismen und Autorisierungsregeln zu umgehen, Daten zu manipulieren, Informationen offenzulegen oder einen Denial-of-Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FasterXML Jackson ausnutzen, um  Schutzmechanismen und Autorisierungsregeln zu umgehen, Daten zu manipulieren, Informationen offenzulegen oder einen Denial-of-Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2058</guid>
    </item>
  </channel>
</rss>
