<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:18:33 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-22754 — ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-22754</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Spring Security, Red Hat OpenShift Developer Tools and Services, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Quarkus, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and 3 more&lt;/p&gt;
&lt;p&gt;Vulnerability in Spring Spring Security. If an application uses &amp;lt;sec:intercept-url servlet-path=&amp;#34;/servlet-path&amp;#34; pattern=&amp;#34;/endpoint/**&amp;#34;/&amp;gt; to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Spring Security, Red Hat OpenShift Developer Tools and Services, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Quarkus, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and 3 more&lt;/p&gt;
&lt;p&gt;Vulnerability in Spring Spring Security. If an application uses &amp;lt;sec:intercept-url servlet-path=&amp;#34;/servlet-path&amp;#34; pattern=&amp;#34;/endpoint/**&amp;#34;/&amp;gt; to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-22754</guid>
    </item>
  </channel>
</rss>
