<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 02:10:36 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1032 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1032</link>
      <description>certfr-2026-avi-1032</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1032</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AH35927 — DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used w…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ah35927</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: wso2is&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the wso2is package. DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: wso2is&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the wso2is package. DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ah35927</guid>
    </item>
    <item>
      <title>EUVD-2026-349180</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349180</link>
      <description>EUVD-2026-349180</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349180</guid>
    </item>
    <item>
      <title>fkie_cve-2026-57819</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57819</link>
      <description>&lt;p&gt;Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the &amp;#34;maxFormParameterCount&amp;#34; configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the &amp;#34;maxFormParameterCount&amp;#34; configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-57819</guid>
    </item>
    <item>
      <title>GHSA-rqrh-ghmh-74j5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rqrh-ghmh-74j5</link>
      <description>&lt;p&gt;Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the &amp;#34;maxFormParameterCount&amp;#34; configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the &amp;#34;maxFormParameterCount&amp;#34; configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rqrh-ghmh-74j5</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2682 — Apache CXF: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2682</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache CXF ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache CXF ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2682</guid>
    </item>
  </channel>
</rss>
