<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from bitnami_vulndb</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:15 +0000</lastBuildDate>
    <item>
      <title>BIT-parse-2026-100632 — Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery</title>
      <link>https://cve.radiocsirt.org/vuln/bit-parse-2026-100632</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: parse&lt;/p&gt;
&lt;p&gt;Parse Server is an open-source backend server. In versions &amp;gt;= 9.0.0 and &amp;lt; 9.10.1, and in versions &amp;lt; 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber&amp;#39;s roles are not resolved, and when a subscription does not supply its own session token the event payload is redacted against an anonymous identity even though the read was authorized against the connected user. As a result, field masks defined for a role, for authenticated users, or for a specific user are not applied, so an authenticated subscriber can receive field values that the REST API correctly withholds and can use a masked field to filter or watch a subscription. Only classes with LiveQuery enabled that define protectedFields under a role:, authenticated, or per-user group are affected; masks under the public (*) group are applied correctly. The issue is fixed in 9.10.1 and 8.6.89. As a workaround, additionally define the affected field masks under the public (*) group, or disable LiveQuery for classes whose class-level permissions rely on role-scoped, authenticated, or per-user protectedFields groups.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: parse&lt;/p&gt;
&lt;p&gt;Parse Server is an open-source backend server. In versions &amp;gt;= 9.0.0 and &amp;lt; 9.10.1, and in versions &amp;lt; 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber&amp;#39;s roles are not resolved, and when a subscription does not supply its own session token the event payload is redacted against an anonymous identity even though the read was authorized against the connected user. As a result, field masks defined for a role, for authenticated users, or for a specific user are not applied, so an authenticated subscriber can receive field values that the REST API correctly withholds and can use a masked field to filter or watch a subscription. Only classes with LiveQuery enabled that define protectedFields under a role:, authenticated, or per-user group are affected; masks under the public (*) group are applied correctly. The issue is fixed in 9.10.1 and 8.6.89. As a workaround, additionally define the affected field masks under the public (*) group, or disable LiveQuery for classes whose class-level permissions rely on role-scoped, authenticated, or per-user protectedFields groups.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-parse-2026-100632</guid>
      <pubDate>Thu, 01 Oct 2026 10:36:21 +0000</pubDate>
    </item>
    <item>
      <title>BIT-parse-2026-100631 — Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection</title>
      <link>https://cve.radiocsirt.org/vuln/bit-parse-2026-100631</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: parse&lt;/p&gt;
&lt;p&gt;Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated remote attacker who knows only the public application ID can submit non-string values in these fields to inject query operators, causing the deduplication cleanup — which runs with elevated privileges before class-level permissions are evaluated — to delete every device registration in the application or an attacker-chosen subset of them. No account, session token, master key, or user interaction is required. Deleted registrations cannot be recovered on the server, so push notifications cannot be delivered until every client re-registers. Any deployment that exposes the REST API to clients and uses push notifications is affected in its default configuration. Versions 8.6.90 and 9.10.1 fix the issue by rejecting non-string values with a client error and by scoping the deduplication cleanup to the calling application. No workaround other than upgrading is available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: parse&lt;/p&gt;
&lt;p&gt;Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated remote attacker who knows only the public application ID can submit non-string values in these fields to inject query operators, causing the deduplication cleanup — which runs with elevated privileges before class-level permissions are evaluated — to delete every device registration in the application or an attacker-chosen subset of them. No account, session token, master key, or user interaction is required. Deleted registrations cannot be recovered on the server, so push notifications cannot be delivered until every client re-registers. Any deployment that exposes the REST API to clients and uses push notifications is affected in its default configuration. Versions 8.6.90 and 9.10.1 fix the issue by rejecting non-string values with a client error and by scoping the deduplication cleanup to the calling application. No workaround other than upgrading is available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-parse-2026-100631</guid>
      <pubDate>Thu, 01 Oct 2026 10:36:20 +0000</pubDate>
    </item>
    <item>
      <title>BIT-wordpress-2026-87902</title>
      <link>https://cve.radiocsirt.org/vuln/bit-wordpress-2026-87902</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: wordpress&lt;/p&gt;
&lt;p&gt;An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: wordpress&lt;/p&gt;
&lt;p&gt;An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-wordpress-2026-87902</guid>
      <pubDate>Tue, 29 Sep 2026 09:00:28 +0000</pubDate>
    </item>
    <item>
      <title>BIT-tomcat-2026-87022 — Apache Tomcat: WebSocket message smuggling with per-message-deflate</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2026-87022</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.25, from 10.1.0 through 10.1.59, from 9.0.0 through 9.0.121.&lt;/p&gt;
&lt;p&gt;The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.56 through 7.0.109. Other unsupported versions may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.1.22, which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.25, from 10.1.0 through 10.1.59, from 9.0.0 through 9.0.121.&lt;/p&gt;
&lt;p&gt;The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.56 through 7.0.109. Other unsupported versions may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.1.22, which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2026-87022</guid>
      <pubDate>Thu, 01 Oct 2026 09:36:37 +0000</pubDate>
    </item>
    <item>
      <title>BIT-tomcat-2026-86350 — Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2026-86350</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Inconsistent interpretation of HTTP/2 requests (&amp;#39;HTTP Request/Response smuggling&amp;#39;) vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Inconsistent interpretation of HTTP/2 requests (&amp;#39;HTTP Request/Response smuggling&amp;#39;) vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2026-86350</guid>
      <pubDate>Thu, 01 Oct 2026 09:36:35 +0000</pubDate>
    </item>
    <item>
      <title>BIT-tomcat-2026-86248 — Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is d…</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2026-86248</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2026-86248</guid>
      <pubDate>Thu, 01 Oct 2026 09:36:34 +0000</pubDate>
    </item>
    <item>
      <title>BIT-tomcat-2026-79677 — Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2026-79677</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.25, from 10.1.0 through 10.1.59, from 9.0.0 through 9.0.121.&lt;/p&gt;
&lt;p&gt;The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.25, from 10.1.0 through 10.1.59, from 9.0.0 through 9.0.121.&lt;/p&gt;
&lt;p&gt;The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2026-79677</guid>
      <pubDate>Thu, 01 Oct 2026 09:36:33 +0000</pubDate>
    </item>
    <item>
      <title>BIT-tomcat-2026-78437 — Apache Tomcat: HTTP/2 DoS via malformed request</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2026-78437</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2026-78437</guid>
      <pubDate>Thu, 01 Oct 2026 09:36:32 +0000</pubDate>
    </item>
    <item>
      <title>BIT-tomcat-2026-78383 — Apache Tomcat: AJP DoS via missing request body</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2026-78383</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.25, from 10.1.0 through 10.1.59, from 9.0.0 through 9.0.121.&lt;/p&gt;
&lt;p&gt;The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.25, from 10.1.0 through 10.1.59, from 9.0.0 through 9.0.121.&lt;/p&gt;
&lt;p&gt;The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2026-78383</guid>
      <pubDate>Thu, 01 Oct 2026 09:36:30 +0000</pubDate>
    </item>
    <item>
      <title>BIT-tomcat-2026-77791 — Apache Tomcat: DoS via busy wait during WebSocket close</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2026-77791</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.25, from 10.1.8 through 10.1.59, from 9.0.74 through 9.0.121.&lt;/p&gt;
&lt;p&gt;The following versions were EOL at the time the CVE was created but are 
known to be affected: from 8.5.88 through 8.5.100. Other unsupported versions may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.25, from 10.1.8 through 10.1.59, from 9.0.74 through 9.0.121.&lt;/p&gt;
&lt;p&gt;The following versions were EOL at the time the CVE was created but are 
known to be affected: from 8.5.88 through 8.5.100. Other unsupported versions may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2026-77791</guid>
      <pubDate>Thu, 01 Oct 2026 09:36:29 +0000</pubDate>
    </item>
  </channel>
</rss>
