<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:12:59.844332+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00270</id>
    <title>bdu:2022-00270</title>
    <updated>2026-10-03T08:12:59.856871+00:00</updated>
    <content>bdu:2022-00270</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00270"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2019-17567</id>
    <title>Withdrawn: BELL-CVE-2019-17567 — CVE-2019-17567 does not affect BellSoft software</title>
    <updated>2026-10-03T08:12:59.856911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2019-17567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575</id>
    <title>certfr-2024-avi-0575 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
    <updated>2026-10-03T08:12:59.856930+00:00</updated>
    <content>certfr-2024-avi-0575</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-44766</id>
    <title>cnvd-2021-44766</title>
    <updated>2026-10-03T08:12:59.856946+00:00</updated>
    <content>cnvd-2021-44766</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-44766"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-58415</id>
    <title>EUVD-2026-58415</title>
    <updated>2026-10-03T08:12:59.856957+00:00</updated>
    <content>EUVD-2026-58415</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-58415"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-17567</id>
    <title>fkie_cve-2019-17567</title>
    <updated>2026-10-03T08:12:59.856968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-17567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qf63-wqjv-7x2f</id>
    <title>GHSA-qf63-wqjv-7x2f</title>
    <updated>2026-10-03T08:12:59.856994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qf63-wqjv-7x2f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-17567</id>
    <title>gsd-2019-17567</title>
    <updated>2026-10-03T08:12:59.857009+00:00</updated>
    <content>gsd-2019-17567</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-17567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2019-17567</id>
    <title>msrc_CVE-2019-17567 — mod_proxy_wstunnel tunneling of non Upgraded connections</title>
    <updated>2026-10-03T08:12:59.857019+00:00</updated>
    <content>msrc_CVE-2019-17567</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2019-17567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1222</id>
    <title>OESA-2023-1222 — httpd security update</title>
    <updated>2026-10-03T08:12:59.857033+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP3: httpd</p>
<p>Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.

Security Fix(es):

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.(CVE-2019-17567)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1222"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:4613</id>
    <title>RHSA-2021:4613 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP10 security update</title>
    <updated>2026-10-03T08:12:59.857054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>httpd: mod_proxy_wstunnel tunneling of non Upgraded connection pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1 httpd: mod_proxy NULL pointer dereference pcre: Integer overflow when parsing callout numeric arguments httpd: Single zero byte stack overflow in mod_auth_digest JBCS: URL normalization issue with dot-dot-semicolon(s) leads to information disclosure openssl: Read buffer overruns processing ASN.1 strings openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash() httpd: mod_session: NULL pointer dereference when parsing Cookie header httpd: mod_session: Heap overflow via a crafted SessionHeader value httpd: Unexpected URL matching with 'MergeSlashes OFF' httpd: NULL pointer dereference via malformed requests</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:4613"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-17567</id>
    <title>UBUNTU-CVE-2019-17567</title>
    <updated>2026-10-03T08:12:59.857090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2</p>
<p>Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-17567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0438</id>
    <title>WID-SEC-W-2022-0438 — Apache HTTP Server: Mehrere Schwachstellen</title>
    <updated>2026-10-03T08:12:59.857112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder sonstige Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0438"/>
  </entry>
</feed>
