<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 18:59:52 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-59250 — JDBC Driver for SQL Server Spoofing Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-59250</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Microsoft JDBC Driver for SQL Server 10.2, Microsoft JDBC Driver for SQL Server 11.2, Microsoft JDBC Driver for SQL Server 12.10, Microsoft JDBC Driver for SQL Server 12.2, Microsoft JDBC Driver for SQL Server 12.4, Microsoft JDBC Driver for SQL Server 12.6, Microsoft JDBC Driver for SQL Server 12.8, Microsoft JDBC Driver for SQL Server 13.2&lt;/p&gt;
&lt;p&gt;Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Microsoft JDBC Driver for SQL Server 10.2, Microsoft JDBC Driver for SQL Server 11.2, Microsoft JDBC Driver for SQL Server 12.10, Microsoft JDBC Driver for SQL Server 12.2, Microsoft JDBC Driver for SQL Server 12.4, Microsoft JDBC Driver for SQL Server 12.6, Microsoft JDBC Driver for SQL Server 12.8, Microsoft JDBC Driver for SQL Server 13.2&lt;/p&gt;
&lt;p&gt;Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-59250</guid>
    </item>
    <item>
      <title>GHSA-2m67-wjpj-xhg9 — Jackson Core: Document length constraint bypass in blocking, async, and DataInput parsers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2m67-wjpj-xhg9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: tools.jackson.core:jackson-core&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Jackson Core 3.x does not consistently enforce `StreamReadConstraints.maxDocumentLength`. Oversized JSON documents can be accepted without a `StreamConstraintsException` in multiple parser entry points, which allows configured size limits to be bypassed and weakens denial-of-service protections.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Three code paths where `maxDocumentLength` is not fully enforced:&lt;/p&gt;
&lt;p&gt;### 1. Blocking parsers skip validation of the final in-memory buffer&lt;/p&gt;
&lt;p&gt;Blocking parsers validate only previously processed buffers, not the final in-memory buffer:&lt;/p&gt;
&lt;p&gt;- `ReaderBasedJsonParser.java:255`
- `UTF8StreamJsonParser.java:208`&lt;/p&gt;
&lt;p&gt;Relevant code:&lt;/p&gt;
&lt;p&gt;```java
_currInputProcessed += bufSize;
_streamReadConstraints.validateDocumentLength(_currInputProcessed);
```&lt;/p&gt;
&lt;p&gt;This means the check occurs only when a completed buffer is rolled over. If an oversized document is fully contained in the final buffer, parsing can complete without any document-length exception.&lt;/p&gt;
&lt;p&gt;### 2. Async parsers skip validation of the final chunk on end-of-input&lt;/p&gt;
&lt;p&gt;Async parsers validate previously processed chunks, but do not validate the final chunk on end-of-input:&lt;/p&gt;
&lt;p&gt;- `NonBlockingByteArrayJsonParser.java:49`
- `NonBlockingByteBufferJsonParser.java:57`
- `NonBlockingUtf8JsonParserBase.java:75`&lt;/p&gt;
&lt;p&gt;Relevant code:&lt;/p&gt;
&lt;p&gt;```java
_currInputProcessed += _origBufferLen;
_streamReadConstraints.validateDocumentLength(_currInputProcessed);&lt;/p&gt;
&lt;p&gt;public void endOfInput() {
    _endOfInput = true;
}
```&lt;/p&gt;
&lt;p&gt;`endOfInput()` marks EOF but does not perform a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: tools.jackson.core:jackson-core&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Jackson Core 3.x does not consistently enforce `StreamReadConstraints.maxDocumentLength`. Oversized JSON documents can be accepted without a `StreamConstraintsException` in multiple parser entry points, which allows configured size limits to be bypassed and weakens denial-of-service protections.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;Three code paths where `maxDocumentLength` is not fully enforced:&lt;/p&gt;
&lt;p&gt;### 1. Blocking parsers skip validation of the final in-memory buffer&lt;/p&gt;
&lt;p&gt;Blocking parsers validate only previously processed buffers, not the final in-memory buffer:&lt;/p&gt;
&lt;p&gt;- `ReaderBasedJsonParser.java:255`
- `UTF8StreamJsonParser.java:208`&lt;/p&gt;
&lt;p&gt;Relevant code:&lt;/p&gt;
&lt;p&gt;```java
_currInputProcessed += bufSize;
_streamReadConstraints.validateDocumentLength(_currInputProcessed);
```&lt;/p&gt;
&lt;p&gt;This means the check occurs only when a completed buffer is rolled over. If an oversized document is fully contained in the final buffer, parsing can complete without any document-length exception.&lt;/p&gt;
&lt;p&gt;### 2. Async parsers skip validation of the final chunk on end-of-input&lt;/p&gt;
&lt;p&gt;Async parsers validate previously processed chunks, but do not validate the final chunk on end-of-input:&lt;/p&gt;
&lt;p&gt;- `NonBlockingByteArrayJsonParser.java:49`
- `NonBlockingByteBufferJsonParser.java:57`
- `NonBlockingUtf8JsonParserBase.java:75`&lt;/p&gt;
&lt;p&gt;Relevant code:&lt;/p&gt;
&lt;p&gt;```java
_currInputProcessed += _origBufferLen;
_streamReadConstraints.validateDocumentLength(_currInputProcessed);&lt;/p&gt;
&lt;p&gt;public void endOfInput() {
    _endOfInput = true;
}
```&lt;/p&gt;
&lt;p&gt;`endOfInput()` marks EOF but does not perform a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2m67-wjpj-xhg9</guid>
    </item>
  </channel>
</rss>
