<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 14:38:25 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-44672 — mapfish-print: Remote Code Injection (RCE) in Dynamic table</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-44672</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; mapfish-print, camptocamp mapfish_print, org.mapfish print.print-lib, org.mapfish print.print-servlet&lt;/p&gt;
&lt;p&gt;mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code  in Dynamic table without being authenticated. This vulnerability is fixed in 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; mapfish-print, camptocamp mapfish_print, org.mapfish print.print-lib, org.mapfish print.print-servlet&lt;/p&gt;
&lt;p&gt;mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code  in Dynamic table without being authenticated. This vulnerability is fixed in 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-44672</guid>
    </item>
  </channel>
</rss>
