<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 09:45:17 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-22747 — Unauthorized User Impersonation when Using X.509 Client Certificates</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-22747</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Spring Security, Red Hat OpenShift Developer Tools and Services, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Quarkus, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and 3 more&lt;/p&gt;
&lt;p&gt;Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
This issue affects Spring Security: from 7.0.0 through 7.0.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Spring Security, Red Hat OpenShift Developer Tools and Services, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Quarkus, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and 3 more&lt;/p&gt;
&lt;p&gt;Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
This issue affects Spring Security: from 7.0.0 through 7.0.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-22747</guid>
    </item>
  </channel>
</rss>
