<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 06:30:37 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329843</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329843</link>
      <description>EUVD-2026-329843</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329843</guid>
    </item>
    <item>
      <title>fkie_cve-2026-57303</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57303</link>
      <description>&lt;p&gt;Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-57303</guid>
    </item>
    <item>
      <title>GHSA-2q27-6p2h-q6r3 — Jenkins Assembla Plugin has an XXE vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2q27-6p2h-q6r3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:assembla&lt;/p&gt;
&lt;p&gt;Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when parsing responses from the configured Assembla server.&lt;/p&gt;
&lt;p&gt;This allows attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.&lt;/p&gt;
&lt;p&gt;As of publication of this advisory, there is no fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.plugins:assembla&lt;/p&gt;
&lt;p&gt;Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when parsing responses from the configured Assembla server.&lt;/p&gt;
&lt;p&gt;This allows attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.&lt;/p&gt;
&lt;p&gt;As of publication of this advisory, there is no fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2q27-6p2h-q6r3</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2074 — Jenkins Plugins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2074</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen zu manipulieren oder offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen zu manipulieren oder offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2074</guid>
    </item>
  </channel>
</rss>
