<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:34:44 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AB17721 — Security fixes in solr 10.0.0-r6</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ab17721</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: solr&lt;/p&gt;
&lt;p&gt;Package solr version 10.0.0-r6 fixes 4 vulnerabilities: CVE-2026-8384, CVE-2026-6790, CVE-2026-10051, CVE-2026-10050&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: solr&lt;/p&gt;
&lt;p&gt;Package solr version 10.0.0-r6 fixes 4 vulnerabilities: CVE-2026-8384, CVE-2026-6790, CVE-2026-10051, CVE-2026-10050&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ab17721</guid>
    </item>
    <item>
      <title>EUVD-2026-336255</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336255</link>
      <description>EUVD-2026-336255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336255</guid>
    </item>
    <item>
      <title>fkie_cve-2026-8384</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8384</link>
      <description>&lt;p&gt;In Eclipse Jetty, an HTTP URI of this form:&lt;/p&gt;
&lt;p&gt;/public;/../admin/secret.txt&lt;/p&gt;
&lt;p&gt;results in an unresolved path of:&lt;/p&gt;
&lt;p&gt;/public/../admin/secret.txt&lt;/p&gt;
&lt;p&gt;instead of the expected:&lt;/p&gt;
&lt;p&gt;/admin/secret.txt&lt;/p&gt;
&lt;p&gt;Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served).&lt;/p&gt;
&lt;p&gt;However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Eclipse Jetty, an HTTP URI of this form:&lt;/p&gt;
&lt;p&gt;/public;/../admin/secret.txt&lt;/p&gt;
&lt;p&gt;results in an unresolved path of:&lt;/p&gt;
&lt;p&gt;/public/../admin/secret.txt&lt;/p&gt;
&lt;p&gt;instead of the expected:&lt;/p&gt;
&lt;p&gt;/admin/secret.txt&lt;/p&gt;
&lt;p&gt;Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served).&lt;/p&gt;
&lt;p&gt;However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-8384</guid>
    </item>
    <item>
      <title>GHSA-w7x5-g22v-xqhr — Eclipse Jetty: Path parameter traversal</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w7x5-g22v-xqhr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty:jetty-util&lt;/p&gt;
&lt;p&gt;### Description (as reported)&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;In Jetty 12.1.8, org.eclipse.jetty.util.URIUtil.canonicalPath() may leave dot-dot path segments unnormalized when a semicolon path parameter marker is followed by a slash and a dot
  segment.&lt;/p&gt;
&lt;p&gt;A minimal example is:&lt;/p&gt;
&lt;p&gt;`/public;/../admin/secret`&lt;/p&gt;
&lt;p&gt;In my local reproduction, URIUtil.canonicalPath() returns:&lt;/p&gt;
&lt;p&gt;`/public/../admin/secret`&lt;/p&gt;
&lt;p&gt;instead of the expected normalized path:&lt;/p&gt;
&lt;p&gt;`/admin/secret`&lt;/p&gt;
&lt;p&gt;When Jetty&amp;#39;s `SecurityHandler.PathMapped` is used to protect a path prefix such as `/admin/*`, the non-normalized canonical path may not match the protected prefix. As a result, an unauthenticated request may bypass the configured path-based security constraint.&lt;/p&gt;
&lt;p&gt;#### Tested Version&lt;/p&gt;
&lt;p&gt;Jetty: 12.1.8
JDK: 17.0.18
Maven: 3.9.14&lt;/p&gt;
&lt;p&gt;Maven artifacts used:&lt;/p&gt;
&lt;p&gt;org.eclipse.jetty:jetty-server:12.1.8
  org.eclipse.jetty:jetty-security:12.1.8
  org.eclipse.jetty:jetty-session:12.1.8&lt;/p&gt;
&lt;p&gt;Only confirmed Jetty 12.1.8 so far.&lt;/p&gt;
&lt;p&gt;#### Minimal Reproduction&lt;/p&gt;
&lt;p&gt;Starts a minimal Jetty server with the following security setup:&lt;/p&gt;
&lt;p&gt;```java
SecurityHandler.PathMapped security = new SecurityHandler.PathMapped();
security.put(&amp;#34;/admin/*&amp;#34;, Constraint.from(&amp;#34;admin&amp;#34;));
security.put(&amp;#34;/*&amp;#34;, Constraint.ALLOWED);
security.setAuthenticator(new BasicAuthenticator());
```&lt;/p&gt;
&lt;p&gt;The test then sends requests with no `Authorization` header.&lt;/p&gt;
&lt;p&gt;Observed result:&lt;/p&gt;
&lt;p&gt;```
GET /admin/secret                  -&amp;gt; 401
GET /public;x/../admin/secret      -&amp;gt; 200
```&lt;/p&gt;
&lt;p&gt;The handler receives paths such as:&lt;/p&gt;
&lt;p&gt;`/public/../admi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty:jetty-util&lt;/p&gt;
&lt;p&gt;### Description (as reported)&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;In Jetty 12.1.8, org.eclipse.jetty.util.URIUtil.canonicalPath() may leave dot-dot path segments unnormalized when a semicolon path parameter marker is followed by a slash and a dot
  segment.&lt;/p&gt;
&lt;p&gt;A minimal example is:&lt;/p&gt;
&lt;p&gt;`/public;/../admin/secret`&lt;/p&gt;
&lt;p&gt;In my local reproduction, URIUtil.canonicalPath() returns:&lt;/p&gt;
&lt;p&gt;`/public/../admin/secret`&lt;/p&gt;
&lt;p&gt;instead of the expected normalized path:&lt;/p&gt;
&lt;p&gt;`/admin/secret`&lt;/p&gt;
&lt;p&gt;When Jetty&amp;#39;s `SecurityHandler.PathMapped` is used to protect a path prefix such as `/admin/*`, the non-normalized canonical path may not match the protected prefix. As a result, an unauthenticated request may bypass the configured path-based security constraint.&lt;/p&gt;
&lt;p&gt;#### Tested Version&lt;/p&gt;
&lt;p&gt;Jetty: 12.1.8
JDK: 17.0.18
Maven: 3.9.14&lt;/p&gt;
&lt;p&gt;Maven artifacts used:&lt;/p&gt;
&lt;p&gt;org.eclipse.jetty:jetty-server:12.1.8
  org.eclipse.jetty:jetty-security:12.1.8
  org.eclipse.jetty:jetty-session:12.1.8&lt;/p&gt;
&lt;p&gt;Only confirmed Jetty 12.1.8 so far.&lt;/p&gt;
&lt;p&gt;#### Minimal Reproduction&lt;/p&gt;
&lt;p&gt;Starts a minimal Jetty server with the following security setup:&lt;/p&gt;
&lt;p&gt;```java
SecurityHandler.PathMapped security = new SecurityHandler.PathMapped();
security.put(&amp;#34;/admin/*&amp;#34;, Constraint.from(&amp;#34;admin&amp;#34;));
security.put(&amp;#34;/*&amp;#34;, Constraint.ALLOWED);
security.setAuthenticator(new BasicAuthenticator());
```&lt;/p&gt;
&lt;p&gt;The test then sends requests with no `Authorization` header.&lt;/p&gt;
&lt;p&gt;Observed result:&lt;/p&gt;
&lt;p&gt;```
GET /admin/secret                  -&amp;gt; 401
GET /public;x/../admin/secret      -&amp;gt; 200
```&lt;/p&gt;
&lt;p&gt;The handler receives paths such as:&lt;/p&gt;
&lt;p&gt;`/public/../admi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w7x5-g22v-xqhr</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-8384</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8384</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: jetty9, Ubuntu:18.04:LTS: jetty9, Ubuntu:20.04:LTS: jetty9, Ubuntu:22.04:LTS: jetty9, Ubuntu:24.04:LTS: jetty9, Ubuntu:26.04:LTS: jetty12, Ubuntu:26.04:LTS: jetty9&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served). However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: jetty9, Ubuntu:18.04:LTS: jetty9, Ubuntu:20.04:LTS: jetty9, Ubuntu:22.04:LTS: jetty9, Ubuntu:24.04:LTS: jetty9, Ubuntu:26.04:LTS: jetty12, Ubuntu:26.04:LTS: jetty9&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served). However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8384</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2314 — Eclipse Jetty: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2314</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2314</guid>
    </item>
  </channel>
</rss>
