<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:42:10 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-1605</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-1605</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Eclipse Foundation Eclipse Jetty, Red Hat HawtIO HawtIO 4.4.0, Red Hat AMQ Broker 7.14.0, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat OpenShift Developer Tools and Services 4.12, Red Hat OpenShift Developer Tools and Services 4.13, Red Hat OpenShift Developer Tools and Services 4.14, Red Hat OpenShift Developer Tools and Services 4.15 and 28 more&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed.&lt;/p&gt;
&lt;p&gt;This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response.
In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Eclipse Foundation Eclipse Jetty, Red Hat HawtIO HawtIO 4.4.0, Red Hat AMQ Broker 7.14.0, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat OpenShift Developer Tools and Services 4.12, Red Hat OpenShift Developer Tools and Services 4.13, Red Hat OpenShift Developer Tools and Services 4.14, Red Hat OpenShift Developer Tools and Services 4.15 and 28 more&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed.&lt;/p&gt;
&lt;p&gt;This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response.
In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-1605</guid>
    </item>
    <item>
      <title>GHSA-3677-xxcr-wjqv — jose4j is vulnerable to DoS via compressed JWE content</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3677-xxcr-wjqv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.bitbucket.b_c:jose4j&lt;/p&gt;
&lt;p&gt;In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.bitbucket.b_c:jose4j&lt;/p&gt;
&lt;p&gt;In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3677-xxcr-wjqv</guid>
    </item>
  </channel>
</rss>
