<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:21:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265585</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265585</link>
      <description>EUVD-2026-265585</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265585</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68704</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68704</link>
      <description>&lt;p&gt;Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68704</guid>
    </item>
    <item>
      <title>GHSA-c9q6-g3hr-8gww — Jervis Has Weak Random for Timing Attack Mitigation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c9q6-g3hr-8gww</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: net.gleske:jervis&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L593-L594&lt;/p&gt;
&lt;p&gt;Uses `java.util.Random()` which is not cryptographically secure.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If an attacker can predict the random delays, they may still be able to perform timing attacks.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Jervis will use `SecureRandom` for timing randomization.&lt;/p&gt;
&lt;p&gt;Upgrade to Jervis 2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [OWASP Cryptographic Failures](https://owasp.org/Top10/A02_2021-Cryptographic_Failures/)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: net.gleske:jervis&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L593-L594&lt;/p&gt;
&lt;p&gt;Uses `java.util.Random()` which is not cryptographically secure.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If an attacker can predict the random delays, they may still be able to perform timing attacks.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Jervis will use `SecureRandom` for timing randomization.&lt;/p&gt;
&lt;p&gt;Upgrade to Jervis 2.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- [OWASP Cryptographic Failures](https://owasp.org/Top10/A02_2021-Cryptographic_Failures/)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c9q6-g3hr-8gww</guid>
    </item>
  </channel>
</rss>
