<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:35:42 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-1225 — Malicious logback.xml configuration file allows instantiation of arbitrary classes</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-1225</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; QOS.CH Sarl Logback-core&lt;/p&gt;
&lt;p&gt;ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.&lt;/p&gt;
&lt;p&gt;The instantiation of a potentially malicious Java class requires that said class is present on the user&amp;#39;s class-path. In addition, the attacker must  have write access to a 
configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; QOS.CH Sarl Logback-core&lt;/p&gt;
&lt;p&gt;ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.&lt;/p&gt;
&lt;p&gt;The instantiation of a potentially malicious Java class requires that said class is present on the user&amp;#39;s class-path. In addition, the attacker must  have write access to a 
configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-1225</guid>
    </item>
    <item>
      <title>GHSA-4773-3jfm-qmx3 — Spring Framework Improper Path Limitation with Script View Templates</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4773-3jfm-qmx3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-webmvc, Maven: org.springframework:spring-webflux&lt;/p&gt;
&lt;p&gt;Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-webmvc, Maven: org.springframework:spring-webflux&lt;/p&gt;
&lt;p&gt;Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4773-3jfm-qmx3</guid>
    </item>
  </channel>
</rss>
