<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 22:09:00 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0504 — De multiples vulnérabilités ont été découvertes dans Spring. Certaines d'entre elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0504</link>
      <description>certfr-2026-avi-0504</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0504</guid>
    </item>
    <item>
      <title>EUVD-2026-306143</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-306143</link>
      <description>EUVD-2026-306143</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-306143</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40969</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40969</link>
      <description>&lt;p&gt;The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks.&lt;/p&gt;
&lt;p&gt;Affected versions:
Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks.&lt;/p&gt;
&lt;p&gt;Affected versions:
Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40969</guid>
    </item>
    <item>
      <title>GHSA-37w2-q6vh-45v6 — Spring gRPC AuthenticationException messages are reflected to remote client</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-37w2-q6vh-45v6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.grpc:spring-grpc&lt;/p&gt;
&lt;p&gt;The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks.&lt;/p&gt;
&lt;p&gt;Affected versions:
Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.grpc:spring-grpc&lt;/p&gt;
&lt;p&gt;The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks.&lt;/p&gt;
&lt;p&gt;Affected versions:
Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-37w2-q6vh-45v6</guid>
    </item>
  </channel>
</rss>
