<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 10:32:21 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-LA97257 — Security fix for ghsa-4vrc-j85c-598c applied in: apache-nifi-registry 2.9.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-la97257</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi-registry&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the apache-nifi-registry package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-nifi-registry&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the apache-nifi-registry package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-la97257</guid>
    </item>
    <item>
      <title>CVE-2026-22754 — ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-22754</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Spring Security, Red Hat OpenShift Developer Tools and Services, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Quarkus, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and 3 more&lt;/p&gt;
&lt;p&gt;Vulnerability in Spring Spring Security. If an application uses &amp;lt;sec:intercept-url servlet-path=&amp;#34;/servlet-path&amp;#34; pattern=&amp;#34;/endpoint/**&amp;#34;/&amp;gt; to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Spring Security, Red Hat OpenShift Developer Tools and Services, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Quarkus, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and 3 more&lt;/p&gt;
&lt;p&gt;Vulnerability in Spring Spring Security. If an application uses &amp;lt;sec:intercept-url servlet-path=&amp;#34;/servlet-path&amp;#34; pattern=&amp;#34;/endpoint/**&amp;#34;/&amp;gt; to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-22754</guid>
    </item>
  </channel>
</rss>
