<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:26:02 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-59250 — JDBC Driver for SQL Server Spoofing Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-59250</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Microsoft JDBC Driver for SQL Server 10.2, Microsoft JDBC Driver for SQL Server 11.2, Microsoft JDBC Driver for SQL Server 12.10, Microsoft JDBC Driver for SQL Server 12.2, Microsoft JDBC Driver for SQL Server 12.4, Microsoft JDBC Driver for SQL Server 12.6, Microsoft JDBC Driver for SQL Server 12.8, Microsoft JDBC Driver for SQL Server 13.2&lt;/p&gt;
&lt;p&gt;Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Microsoft JDBC Driver for SQL Server 10.2, Microsoft JDBC Driver for SQL Server 11.2, Microsoft JDBC Driver for SQL Server 12.10, Microsoft JDBC Driver for SQL Server 12.2, Microsoft JDBC Driver for SQL Server 12.4, Microsoft JDBC Driver for SQL Server 12.6, Microsoft JDBC Driver for SQL Server 12.8, Microsoft JDBC Driver for SQL Server 13.2&lt;/p&gt;
&lt;p&gt;Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-59250</guid>
    </item>
    <item>
      <title>GHSA-3qp7-7mw8-wx86 — Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3qp7-7mw8-wx86</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-handler&lt;/p&gt;
&lt;p&gt;### Summary
An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions.&lt;/p&gt;
&lt;p&gt;### Details
`io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress)` method performs a bitwise AND between the incoming IP address and the configured networkAddress, instead of the subnetMask.&lt;/p&gt;
&lt;p&gt;### Impact
Access Control Bypass. Attacker can bypass IpSubnetFilter IPv6 access controls.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-handler&lt;/p&gt;
&lt;p&gt;### Summary
An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions.&lt;/p&gt;
&lt;p&gt;### Details
`io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress)` method performs a bitwise AND between the incoming IP address and the configured networkAddress, instead of the subnetMask.&lt;/p&gt;
&lt;p&gt;### Impact
Access Control Bypass. Attacker can bypass IpSubnetFilter IPv6 access controls.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3qp7-7mw8-wx86</guid>
    </item>
  </channel>
</rss>
