<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 05:03:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292649</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292649</link>
      <description>EUVD-2026-292649</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292649</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40942</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40942</link>
      <description>&lt;p&gt;The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Document caches used an inverted time comparison (isBefore instead of isAfter), causing the cache to never return cached values. Every incoming request triggered a fresh HTTP fetch of the OIDC Metadata Document and JWKS keys from the OIDC provider. The OIDC token cache for the FHIR client connections used an inverted time comparison (isBefore instead of isAfter), causing the cache to never invalidate. Every incoming request returned the same OIDC token even if expired. This vulnerability is fixed in 2.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Document caches used an inverted time comparison (isBefore instead of isAfter), causing the cache to never return cached values. Every incoming request triggered a fresh HTTP fetch of the OIDC Metadata Document and JWKS keys from the OIDC provider. The OIDC token cache for the FHIR client connections used an inverted time comparison (isBefore instead of isAfter), causing the cache to never invalidate. Every incoming request returned the same OIDC token even if expired. This vulnerability is fixed in 2.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40942</guid>
    </item>
    <item>
      <title>GHSA-xmj9-7625-f634 — Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xmj9-7625-f634</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: dev.dsf:dsf-bpe-process-api-v2, Maven: dev.dsf:dsf-bpe-server&lt;/p&gt;
&lt;p&gt;### Affected Components
- DSF FHIR Server with enabled [bearer-token authentication](https://dsf.dev/operations/v2.1.0/fhir/oidc.html) or [back-channel logout](https://dsf.dev/operations/v2.1.0/fhir/oidc.html).
- DSF BPE Server with enabled [bearer-token authentication](https://dsf.dev/operations/v2.1.0/bpe/oidc.html) or [back-channel logout](https://dsf.dev/operations/v2.1.0/bpe/oidc.html).
- DSF BPE Server API v2 process plugins using [FHIR client connections](https://dsf.dev/operations/v2.1.0/bpe/fhir-client-connections.html) with configured OIDC authentication.&lt;/p&gt;
&lt;p&gt;### Summary
- The OIDC JWKS and Metadata Document caches used an inverted time comparison (`isBefore` instead of `isAfter`), causing the cache to **never return cached values**. Every incoming request triggered a fresh HTTP fetch of the OIDC Metadata Document and JWKS keys from the OIDC provider.
- The OIDC token cache for the [FHIR client connections](https://dsf.dev/operations/v2.1.0/bpe/fhir-client-connections.html) used an inverted time comparison (`isBefore` instead of `isAfter`), causing the cache to **never invalidate**. Every incoming request returned the same OIDC token even if expired.&lt;/p&gt;
&lt;p&gt;### Impact
- **Performance:** Every OIDC-authenticated request added network round-trips to the OIDC provider, increasing latency
- **Reliability:** Cached OIDC tokens become unusable after expiration and can only be invalidated by restart of the BPE. 
 If the OIDC provider is temporarily unreachable, all requests fail i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: dev.dsf:dsf-bpe-process-api-v2, Maven: dev.dsf:dsf-bpe-server&lt;/p&gt;
&lt;p&gt;### Affected Components
- DSF FHIR Server with enabled [bearer-token authentication](https://dsf.dev/operations/v2.1.0/fhir/oidc.html) or [back-channel logout](https://dsf.dev/operations/v2.1.0/fhir/oidc.html).
- DSF BPE Server with enabled [bearer-token authentication](https://dsf.dev/operations/v2.1.0/bpe/oidc.html) or [back-channel logout](https://dsf.dev/operations/v2.1.0/bpe/oidc.html).
- DSF BPE Server API v2 process plugins using [FHIR client connections](https://dsf.dev/operations/v2.1.0/bpe/fhir-client-connections.html) with configured OIDC authentication.&lt;/p&gt;
&lt;p&gt;### Summary
- The OIDC JWKS and Metadata Document caches used an inverted time comparison (`isBefore` instead of `isAfter`), causing the cache to **never return cached values**. Every incoming request triggered a fresh HTTP fetch of the OIDC Metadata Document and JWKS keys from the OIDC provider.
- The OIDC token cache for the [FHIR client connections](https://dsf.dev/operations/v2.1.0/bpe/fhir-client-connections.html) used an inverted time comparison (`isBefore` instead of `isAfter`), causing the cache to **never invalidate**. Every incoming request returned the same OIDC token even if expired.&lt;/p&gt;
&lt;p&gt;### Impact
- **Performance:** Every OIDC-authenticated request added network round-trips to the OIDC provider, increasing latency
- **Reliability:** Cached OIDC tokens become unusable after expiration and can only be invalidated by restart of the BPE. 
 If the OIDC provider is temporarily unreachable, all requests fail i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xmj9-7625-f634</guid>
    </item>
  </channel>
</rss>
