<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:06:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-364321</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364321</link>
      <description>EUVD-2026-364321</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364321</guid>
    </item>
    <item>
      <title>fkie_cve-2026-57281</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57281</link>
      <description>&lt;p&gt;Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-57281</guid>
    </item>
    <item>
      <title>GHSA-cfj9-2vgr-hpxp — Jenkins Script Security Plugin has a script security bypass vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cfj9-2vgr-hpxp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:script-security&lt;/p&gt;
&lt;p&gt;Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations such as @CompileStatic and @TypeChecked that carry an extensions member, which causes Groovy to load and execute a script from the classpath at compile time, before the sandbox is applied.&lt;/p&gt;
&lt;p&gt;This may allow attackers able to define and run sandboxed scripts to execute code outside the sandbox, in the rare case that a suitable Groovy script is present on the classpath of the component that evaluates the script.&lt;/p&gt;
&lt;p&gt;The Jenkins security team has been unable to identify any Groovy source files in Jenkins core or plugins that would allow attackers to execute dangerous code. While the severity of this issue is declared as High due to the potential impact, successful exploitation is considered very unlikely.&lt;/p&gt;
&lt;p&gt;Script Security Plugin 1402.1405.vc96e74964250 rejects any annotation carrying an extensions member during sandbox compilation, before Groovy can resolve or execute the referenced script.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:script-security&lt;/p&gt;
&lt;p&gt;Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations such as @CompileStatic and @TypeChecked that carry an extensions member, which causes Groovy to load and execute a script from the classpath at compile time, before the sandbox is applied.&lt;/p&gt;
&lt;p&gt;This may allow attackers able to define and run sandboxed scripts to execute code outside the sandbox, in the rare case that a suitable Groovy script is present on the classpath of the component that evaluates the script.&lt;/p&gt;
&lt;p&gt;The Jenkins security team has been unable to identify any Groovy source files in Jenkins core or plugins that would allow attackers to execute dangerous code. While the severity of this issue is declared as High due to the potential impact, successful exploitation is considered very unlikely.&lt;/p&gt;
&lt;p&gt;Script Security Plugin 1402.1405.vc96e74964250 rejects any annotation carrying an extensions member during sandbox compilation, before Groovy can resolve or execute the referenced script.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cfj9-2vgr-hpxp</guid>
    </item>
    <item>
      <title>RHSA-2026:60239 — Red Hat Security Advisory: Release of Red Hat OpenShift Developer Tools - Openshift Jenkins 4.15 security update.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:60239</link>
      <description>&lt;p&gt;jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid httpclient: Apache HttpClient: Authentication bypass due to missing mutual authentication verification Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix Apache MINA: Apache MINA: Arbitrary code execution via classname allowlist bypass Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409) Apache MINA: Apache MINA: Arbitrary Code Execution via Classname Allowlist Bypass mina: mina: Arbitrary Code Execution via Deserialization Bypass jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing jenkins: Jenkins: Arbitrary code execution via deserialization of attacker-controlled configuration jenkins: Jenkins: Phishing attack via improper red…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid httpclient: Apache HttpClient: Authentication bypass due to missing mutual authentication verification Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix Apache MINA: Apache MINA: Arbitrary code execution via classname allowlist bypass Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409) Apache MINA: Apache MINA: Arbitrary Code Execution via Classname Allowlist Bypass mina: mina: Arbitrary Code Execution via Deserialization Bypass jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing jenkins: Jenkins: Arbitrary code execution via deserialization of attacker-controlled configuration jenkins: Jenkins: Phishing attack via improper red…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:60239</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2074 — Jenkins Plugins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2074</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen zu manipulieren oder offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen zu manipulieren oder offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2074</guid>
    </item>
  </channel>
</rss>
