<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:12:49 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-05080</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-05080</link>
      <description>cnvd-2020-05080</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-05080</guid>
    </item>
    <item>
      <title>EUVD-2026-53940</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-53940</link>
      <description>EUVD-2026-53940</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-53940</guid>
    </item>
    <item>
      <title>fkie_cve-2019-10770</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10770</link>
      <description>&lt;p&gt;All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode error handler when an exception message contains untrusted data. Note the production mode error handler is not vulnerable - so for this to be utilized in production it would require users to not disable development mode.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode error handler when an exception message contains untrusted data. Note the production mode error handler is not vulnerable - so for this to be utilized in production it would require users to not disable development mode.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-10770</guid>
    </item>
    <item>
      <title>GHSA-r2wf-q3x4-hrv9 — Default development error handler in Ratpack is vulnerable to HTML content injection (XSS)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r2wf-q3x4-hrv9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.ratpack:ratpack-core&lt;/p&gt;
&lt;p&gt;Versions of Ratpack from 0.9.10 through 1.7.5 are vulnerable to [CWE-79: Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;)](https://cwe.mitre.org/data/definitions/79.html) (aka. XSS) in the development error handler. An attacker can utilize this to perform XSS when an exception message contains untrusted data.&lt;/p&gt;
&lt;p&gt;As a simplistic example:
```java
RatpackServer startedServer = RatpackServer.start(server -&amp;gt; {
    server.handlers(chain -&amp;gt; chain.all(ctx -&amp;gt; {
        // User supplied query parameter
        String message = ctx.getRequest().getQueryParams().get(&amp;#34;message&amp;#34;);
        // User supplied data appended to the message in an exception
        throw new RuntimeException(&amp;#34;An error occurred: &amp;#34; + message);
    }));
});
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- Cross-Site Scripting&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This vulnerability has been patched in Ratpack version 1.7.6.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If you are unable to update your version of Ratpack, we recommend the following workarounds and mitigations.&lt;/p&gt;
&lt;p&gt;- Ensure that development mode is disabled in production.
 - Don&amp;#39;t use real customer data (ie. untrusted user input) in development.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [Ratpack development mode](https://ratpack.io/manual/current/api/ratpack/server/ServerConfigBuilder.html#development-boolean-)
 - [Code Patch - a3cbb13](https://github.com/ratpack/ratpack/commit/a3cbb13be1527874528c3b99fc33517c0297b6d3)&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:
 - Open an issue i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.ratpack:ratpack-core&lt;/p&gt;
&lt;p&gt;Versions of Ratpack from 0.9.10 through 1.7.5 are vulnerable to [CWE-79: Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;)](https://cwe.mitre.org/data/definitions/79.html) (aka. XSS) in the development error handler. An attacker can utilize this to perform XSS when an exception message contains untrusted data.&lt;/p&gt;
&lt;p&gt;As a simplistic example:
```java
RatpackServer startedServer = RatpackServer.start(server -&amp;gt; {
    server.handlers(chain -&amp;gt; chain.all(ctx -&amp;gt; {
        // User supplied query parameter
        String message = ctx.getRequest().getQueryParams().get(&amp;#34;message&amp;#34;);
        // User supplied data appended to the message in an exception
        throw new RuntimeException(&amp;#34;An error occurred: &amp;#34; + message);
    }));
});
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- Cross-Site Scripting&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This vulnerability has been patched in Ratpack version 1.7.6.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If you are unable to update your version of Ratpack, we recommend the following workarounds and mitigations.&lt;/p&gt;
&lt;p&gt;- Ensure that development mode is disabled in production.
 - Don&amp;#39;t use real customer data (ie. untrusted user input) in development.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [Ratpack development mode](https://ratpack.io/manual/current/api/ratpack/server/ServerConfigBuilder.html#development-boolean-)
 - [Code Patch - a3cbb13](https://github.com/ratpack/ratpack/commit/a3cbb13be1527874528c3b99fc33517c0297b6d3)&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:
 - Open an issue i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r2wf-q3x4-hrv9</guid>
    </item>
    <item>
      <title>gsd-2019-10770</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-10770</link>
      <description>gsd-2019-10770</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-10770</guid>
    </item>
  </channel>
</rss>
