<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:36:06.177342+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-01935</id>
    <title>bdu:2020-01935</title>
    <updated>2026-10-02T18:36:06.210990+00:00</updated>
    <content>bdu:2020-01935</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-01935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-113</id>
    <title>certfr-2022-avi-113 — De multiples vulnérabilités ont été découvertes dans les produits
NetApp. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T18:36:06.211033+00:00</updated>
    <content>certfr-2022-avi-113</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-246531</id>
    <title>EUVD-2026-246531</title>
    <updated>2026-10-02T18:36:06.211052+00:00</updated>
    <content>EUVD-2026-246531</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-246531"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-16869</id>
    <title>fkie_cve-2019-16869</title>
    <updated>2026-10-02T18:36:06.211064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-16869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p979-4mfw-53vg</id>
    <title>GHSA-p979-4mfw-53vg — HTTP Request Smuggling in Netty</title>
    <updated>2026-10-02T18:36:06.211094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.netty:netty-all, Maven: org.jboss.netty:netty, Maven: io.netty:netty</p>
<p>Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p979-4mfw-53vg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-16869</id>
    <title>gsd-2019-16869</title>
    <updated>2026-10-02T18:36:06.211122+00:00</updated>
    <content>gsd-2019-16869</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-16869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2066</id>
    <title>OESA-2024-2066 — netty3 security update</title>
    <updated>2026-10-02T18:36:06.211134+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: netty3</p>
<p>Netty is a NIO client server framework which enables quick and easy development of network applications such as protocol servers and clients. It greatly simplifies and streamlines network programming such as TCP and UDP socket server.

Security Fix(es):

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;quot;Transfer-Encoding : chunked&amp;quot; line), which leads to HTTP request smuggling.(CVE-2019-16869)

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;quot;invalid fold.&amp;quot;(CVE-2019-20444)

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.(CVE-2019-20445)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:3892</id>
    <title>RHSA-2019:3892 — Red Hat Security Advisory: Red Hat Fuse 7.5.0 security update</title>
    <updated>2026-10-02T18:36:06.211160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525) jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-15095) infinispan: deserialization of data in XML and JSON transcoders hadoop: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file tomcat: Host name verification missing in WebSocket client jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis activemq: ActiveMQ Client Missing TLS Hostname Verification tika: Incomplete fix allows for XML entity expansion resulting in denial of service jackson-databind: improper polymorphic deserialization of types from Jodd-db library jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver jackson-databind: arbitrary code execution in slf4j-ext class jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes jackson-databind: exfiltration/XXE in some JDK classes jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class jackson-databind: improper polymorphic deserialization in axis2-transport-jms class jackson-databind: improper polymorphic deserialization in openjpa class jackson-databind: improper polymorphic deserialization in jboss-common-core class retrofit: Directory traversal in RequestBuilder allows manipulation of resources zookeeper: Information disclosure in Apa…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:3892"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16869</id>
    <title>UBUNTU-CVE-2019-16869</title>
    <updated>2026-10-02T18:36:06.211232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: netty, Ubuntu:16.04:LTS: netty-3.9, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:18.04:LTS: netty-3.9, Ubuntu:Pro:18.04:LTS: netty</p>
<p>Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</id>
    <title>WID-SEC-W-2022-0770 — IBM DB2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:36:06.211259+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770"/>
  </entry>
</feed>
