<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 01:34:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-368227</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368227</link>
      <description>EUVD-2026-368227</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368227</guid>
    </item>
    <item>
      <title>fkie_cve-2026-87802</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-87802</link>
      <description>&lt;p&gt;Improper verification of cryptographic signature vulnerability in Apache Syncope.&lt;/p&gt;
&lt;p&gt;When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper verification of cryptographic signature vulnerability in Apache Syncope.&lt;/p&gt;
&lt;p&gt;When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-87802</guid>
    </item>
    <item>
      <title>GHSA-mg52-7466-j5f7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mg52-7466-j5f7</link>
      <description>&lt;p&gt;Improper verification of cryptographic signature vulnerability in Apache Syncope.&lt;/p&gt;
&lt;p&gt;When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper verification of cryptographic signature vulnerability in Apache Syncope.&lt;/p&gt;
&lt;p&gt;When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mg52-7466-j5f7</guid>
    </item>
  </channel>
</rss>
