<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:05:53.580182+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-09054</id>
    <title>bdu:2024-09054</title>
    <updated>2026-10-02T17:05:54.767008+00:00</updated>
    <content>bdu:2024-09054</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-09054"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2018-25091</id>
    <title>Withdrawn: BELL-CVE-2018-25091 — CVE-2018-25091 does not affect BellSoft software</title>
    <updated>2026-10-02T17:05:54.767069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2018-25091"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2018-25091</id>
    <title>BREW-ansible-CVE-2018-25091 — Authorization Header forwarded on redirect</title>
    <updated>2026-10-02T17:05:54.767097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2018-25091"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</id>
    <title>certfr-2024-avi-0646 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T17:05:54.767137+00:00</updated>
    <content>certfr-2024-avi-0646</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-169095</id>
    <title>EUVD-2026-169095</title>
    <updated>2026-10-02T17:05:54.767161+00:00</updated>
    <content>EUVD-2026-169095</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-169095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-25091</id>
    <title>fkie_cve-2018-25091</title>
    <updated>2026-10-02T17:05:54.767178+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-25091"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gwvm-45gx-3cf8</id>
    <title>GHSA-gwvm-45gx-3cf8 — Authorization Header forwarded on redirect</title>
    <updated>2026-10-02T17:05:54.767209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: urllib3</p>
<p>urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gwvm-45gx-3cf8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-25091</id>
    <title>gsd-2018-25091</title>
    <updated>2026-10-02T17:05:54.767256+00:00</updated>
    <content>gsd-2018-25091</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-25091"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2018-25091</id>
    <title>msrc_CVE-2018-25091 — urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a red…</title>
    <updated>2026-10-02T17:05:54.767275+00:00</updated>
    <content>msrc_CVE-2018-25091</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2018-25091"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2023-207</id>
    <title>PYSEC-2023-207</title>
    <updated>2026-10-02T17:05:54.767301+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: urllib3</p>
<p>urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2023-207"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:2988</id>
    <title>RHSA-2024:2988 — Red Hat Security Advisory: container-tools:rhel8 security update</title>
    <updated>2026-10-02T17:05:54.767330+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents golang: crypto/tls: certificate of wrong type is causing TLS client to panic golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters golang: regexp/syntax: limit memory used by parsing regexps golang: crypto/tls: slow verification of certificate chains containing large RSA keys golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. urllib3: Request body not stripped after redirect from 303 status changes request method to GET ssh: Prefix truncation attack on Binary Packet Protocol (BPP) moby/buildkit: Possible race condition with accessing subpaths from cache mounts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:2988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:4352-1</id>
    <title>SUSE-SU-2023:4352-1 — Security update for python-urllib3</title>
    <updated>2026-10-02T17:05:54.767393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-urllib3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:4352-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-25091</id>
    <title>UBUNTU-CVE-2018-25091</title>
    <updated>2026-10-02T17:05:54.767419+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:14.04:LTS: python-urllib3, Ubuntu:Pro:16.04:LTS: python-urllib3, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:18.04:LTS: python-urllib3, Ubuntu:Pro:18.04:LTS: python-pip</p>
<p>urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-25091"/>
  </entry>
</feed>
