<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 09:01:30 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265810</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265810</link>
      <description>EUVD-2026-265810</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265810</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68698</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68698</link>
      <description>&lt;p&gt;Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding). This vulnerability is fixed in 2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding). This vulnerability is fixed in 2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68698</guid>
    </item>
    <item>
      <title>GHSA-mqw7-c5gg-xq97 — Jervis Has a RSA PKCS#1 Padding Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mqw7-c5gg-xq97</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: net.gleske:jervis&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L463-L465&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L495-L497&lt;/p&gt;
&lt;p&gt;Uses `PKCS1Encoding` which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding).&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Severity is considered low for internal uses of this library but if there&amp;#39;s any consumer using these methods directly then this is considered critical.&lt;/p&gt;
&lt;p&gt;An attacker with access to a decryption oracle (e.g., timing differences or error messages) could potentially decrypt ciphertext without knowing the private key.&lt;/p&gt;
&lt;p&gt;Jervis uses RSA to encrypt AES keys in local-only storage inaccessible from the web.  The data stored is GitHub App authentication tokens which will expire within one hour or less.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Jervis patch will migrate from `PKCS1Encoding` to `OAEPEncoding`.&lt;/p&gt;
&lt;p&gt;Upgrade to Jervis 2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [Bleichenbacher&amp;#39;s Attack on PKCS#1](https://en.wikipedia.org/wiki/Adaptive_chosen-ciphertext_attack)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: net.gleske:jervis&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L463-L465&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L495-L497&lt;/p&gt;
&lt;p&gt;Uses `PKCS1Encoding` which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding).&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Severity is considered low for internal uses of this library but if there&amp;#39;s any consumer using these methods directly then this is considered critical.&lt;/p&gt;
&lt;p&gt;An attacker with access to a decryption oracle (e.g., timing differences or error messages) could potentially decrypt ciphertext without knowing the private key.&lt;/p&gt;
&lt;p&gt;Jervis uses RSA to encrypt AES keys in local-only storage inaccessible from the web.  The data stored is GitHub App authentication tokens which will expire within one hour or less.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Jervis patch will migrate from `PKCS1Encoding` to `OAEPEncoding`.&lt;/p&gt;
&lt;p&gt;Upgrade to Jervis 2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [Bleichenbacher&amp;#39;s Attack on PKCS#1](https://en.wikipedia.org/wiki/Adaptive_chosen-ciphertext_attack)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mqw7-c5gg-xq97</guid>
    </item>
  </channel>
</rss>
