<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:36:44.721262+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-02206</id>
    <title>bdu:2022-02206</title>
    <updated>2026-10-03T07:36:44.728416+00:00</updated>
    <content>bdu:2022-02206</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-02206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0357</id>
    <title>certfr-2023-avi-0357 — De multiples vulnérabilités ont été découvertes dans IBM Cognos.
Certaines d'entre elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T07:36:44.728447+00:00</updated>
    <content>certfr-2023-avi-0357</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-28268</id>
    <title>cnvd-2021-28268</title>
    <updated>2026-10-03T07:36:44.728466+00:00</updated>
    <content>cnvd-2021-28268</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-28268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-74855</id>
    <title>EUVD-2026-74855</title>
    <updated>2026-10-03T07:36:44.728478+00:00</updated>
    <content>EUVD-2026-74855</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-74855"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-7658</id>
    <title>fkie_cve-2017-7658</title>
    <updated>2026-10-03T07:36:44.728490+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-7658"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6x9x-8qw9-9pp6</id>
    <title>GHSA-6x9x-8qw9-9pp6 — Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)</title>
    <updated>2026-10-03T07:36:44.728519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.eclipse.jetty:jetty-server</p>
<p>Eclipse Jetty Server versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), are vulnerable to HTTP Request Smuggling when presented with two content-lengths headers, allowing authorization bypass. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decides on the shorter length, but still passes on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary is imposing authorization, the fake pipelined request bypasses that authorization.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6x9x-8qw9-9pp6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-7658</id>
    <title>gsd-2017-7658</title>
    <updated>2026-10-03T07:36:44.728545+00:00</updated>
    <content>gsd-2017-7658</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-7658"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:3779</id>
    <title>RHSA-2020:3779 — Red Hat Security Advisory: Red Hat Data Grid 7.3.7 security update</title>
    <updated>2026-10-03T07:36:44.728557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jetty: HTTP request smuggling using the range header jetty: HTTP request smuggling jetty: Incorrect header handling jackson-mapper-asl: XML external entity similar to CVE-2016-3720 resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class EAP: field-name is not parsed in accordance to RFC7230 Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain undertow: AJP File Read/Inclusion Vulnerability Wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass jackson-databind: Lacks certain xbean-reflect/JNDI blocking log4j: improper validation of certificate with host mismatch in SMTP appender jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution wildfly-elytron: session fixation when using FORM authentication jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider.*.RmiProvider jackson-databind: Serialization gadgets in javax.swing.…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:3779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-7658</id>
    <title>UBUNTU-CVE-2017-7658</title>
    <updated>2026-10-03T07:36:44.728601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: jetty8, Ubuntu:16.04:LTS: jetty8, Ubuntu:16.04:LTS: jetty9, Ubuntu:18.04:LTS: jetty9</p>
<p>In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-7658"/>
  </entry>
</feed>
