<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Graylog</title>
  <link>https://cvedaily.com/pages/tags/graylog.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/graylog.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Graylog</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:00 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-1441 – Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1441</guid>
    <pubDate>Wed, 18 Feb 2026 14:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1441</strong></p>
  <p>Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker to inject and execute arbitrary JavaScript code when a user visits a specially crafted URL. Exploita…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1440 – Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1440</guid>
    <pubDate>Wed, 18 Feb 2026 14:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1440</strong></p>
  <p>Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker to inject and execute arbitrary JavaScript code when a user visits a specially crafted URL. Exploita…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1439 – Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1439</guid>
    <pubDate>Wed, 18 Feb 2026 14:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1439</strong></p>
  <p>Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker to inject and execute arbitrary JavaScript code when a user visits a specially crafted URL. Exploita…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1438 – Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1438</guid>
    <pubDate>Wed, 18 Feb 2026 14:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1438</strong></p>
  <p>Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker to inject and execute arbitrary JavaScript code when a user visits a specially crafted URL. Exploita…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1437 – Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1437</guid>
    <pubDate>Wed, 18 Feb 2026 14:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1437</strong></p>
  <p>Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker to inject and execute arbitrary JavaScript code when a user visits a specially crafted URL. Exploita…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1436 – Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1436</guid>
    <pubDate>Wed, 18 Feb 2026 14:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1436</strong></p>
  <p>Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can access other user's profiles without proper authorization checks. Exploiting this vulnerability allows valid users of the system to be listed and sensitive third-party information to be accessed, such as names, email addresses, internal identifiers, and l…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1435 – Not properly invalidated session vulnerability in Graylog Web Interface, version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1435</guid>
    <pubDate>Wed, 18 Feb 2026 14:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1435</strong></p>
  <p>Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, which remain valid even after multiple consecutive logins by the same user. As a result, a stolen or l…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53106 – Graylog is a free and open log management platform. In versions 6.2.0 to before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53106</guid>
    <pubDate>Wed, 02 Jul 2025 14:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53106</strong></p>
  <p>Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain elevated privileges by creating and using API tokens for the local Administrator or any other user for whom the malicious user knows the ID. For the attack to succeed, the attacker needs a user account in Graylog. They can then proceed to issue hand-…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46827 – Graylog is a free and open log management platform. Prior to versions 6.0.14, 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46827</guid>
    <pubDate>Wed, 07 May 2025 16:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46827</strong></p>
  <p>Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtain user session cookies by submitting an HTML form as part of an Event Definition Remediation Step field. For this attack to succeed, the attacker needs a user account with permissions to create event definitions, while the user must have permissions to view alerts. Additionally,…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30373 – Graylog is a free and open log management platform. Starting with 6.1, HTTP Inpu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30373</guid>
    <pubDate>Mon, 07 Apr 2025 15:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30373</strong></p>
  <p>Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless. To mitigate the vulnerability, d…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52506 – Graylog is a free and open log management platform. The reporting functionality ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52506</guid>
    <pubDate>Mon, 18 Nov 2024 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52506</strong></p>
  <p>Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and scheduling of reports which contain dashboard widgets displaying individual log messages or metrics aggregated from fields of multiple log messages. This functionality, as included in Graylog 6.1.0 & 6.1.1, is vulnerable to information leakage triggered by multiple concurrent report…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24824 – Graylog is a free and open log management platform. Starting in version 2.0.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24824</guid>
    <pubDate>Wed, 07 Feb 2024 18:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24824</strong></p>
  <p>Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. Graylog's cluster config system uses fully qualified class names as config keys. To validate the existence of the requested class before using them, Graylog loa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-24823 – Graylog is a free and open log management platform. Starting in version 4.3.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24823</guid>
    <pubDate>Wed, 07 Feb 2024 18:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-24823</strong></p>
  <p>Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, reauthenticating with an existing session cookie would re-use that session id, even if for different user credentials. In this case, the pre-existing session could be used to gain elevated access to an existing Graylog login session, provided the malicious user could successfully…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-41045 – Graylog is a free and open log management platform. Graylog makes use of only on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41045</guid>
    <pubDate>Thu, 31 Aug 2023 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-41045</strong></p>
  <p>Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Graylog binds a single socket for outgoing DNS queries and while that socket is bound to a random port number it is never changed again. This goes against recommended practice since 2008, when Dan Kaminsky discovered how easy is to carry out DNS cache poisoning attacks. In order t…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-41044 – Graylog is a free and open log management platform. A partial path traversal vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41044</guid>
    <pubDate>Thu, 31 Aug 2023 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-41044</strong></p>
  <p>Graylog is a free and open log management platform. A partial path traversal vulnerability exists in Graylog's `Support Bundle` feature. The vulnerability is caused by incorrect user input validation in an HTTP API resource. Graylog's Support Bundle feature allows an attacker with valid Admin role credentials to download or delete files in sibling directories of the support bundle directory. The…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-41041 – Graylog is a free and open log management platform. In a multi-node Graylog clus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41041</guid>
    <pubDate>Wed, 30 Aug 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-41041</strong></p>
  <p>Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged out, a user session may still be used for API requests until it has reached its original expiry time. Each node maintains an in-memory cache of user sessions. Upon a cache-miss, the session is loaded from the database. After that, the node operates solely on the cached session.…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37760 – A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37760</guid>
    <pubDate>Sat, 31 Jul 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37760</strong></p>
  <p>A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37759 – A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37759</guid>
    <pubDate>Sat, 31 Jul 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37759</strong></p>
  <p>A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15813 – Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15813</guid>
    <pubDate>Fri, 17 Jul 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15813</strong></p>
  <p>Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connection configuration allows the usage of unencrypted, SSL- or TLS-secured connections. Unfortunately, the Graylog client code (in all versions that support LDAP) does not implement proper certificate validation (regardless of whether the "Allow self-sign…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-14380 – In Graylog before 2.4.6, XSS was possible in typeahead components, related to co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14380</guid>
    <pubDate>Wed, 18 Jul 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-14380</strong></p>
  <p>In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-11651 – Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11651</guid>
    <pubDate>Fri, 01 Jun 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-11651</strong></p>
  <p>Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-11650 – Graylog before v2.4.4 has an XSS security issue with unescaped text in notificat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11650</guid>
    <pubDate>Fri, 01 Jun 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-11650</strong></p>
  <p>Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11650">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
