<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T19:26:22.102512+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42665</id>
    <title>EUVD-2026-42665</title>
    <updated>2026-10-07T19:26:22.170244+00:00</updated>
    <content>EUVD-2026-42665</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42665"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15094</id>
    <title>fkie_cve-2020-15094</title>
    <updated>2026-10-07T19:26:22.170290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-15094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-754h-5r27-7x3r</id>
    <title>GHSA-754h-5r27-7x3r — RCE in Symfony</title>
    <updated>2026-10-07T19:26:22.170343+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: symfony/http-kernel, Packagist: symfony/symfony</p>
<p>Description
-----------</p>
<p>The `CachingHttpClient` class from the HttpClient Symfony component relies on the `HttpCache` class to handle requests. `HttpCache` uses internal headers like `X-Body-Eval` and `X-Body-File` to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by `CachingHttpClient` and if an attacker can control the response for a request being made by the `CachingHttpClient`, remote code execution is possible.</p>
<p>Resolution
----------</p>
<p>HTTP headers designed for internal use in `HttpCache` are now stripped from remote responses before being passed to `HttpCache`.</p>
<p>The patch for this issue is available [here](https://github.com/symfony/symfony/commit/d9910e0b33a2e0f993abff41c6fbc86951b66d78) for the 4.4 branch.</p>
<p>Credits
-------</p>
<p>I would like to thank Matthias Pigulla (webfactory GmbH) for reporting and fixing the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-754h-5r27-7x3r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-15094</id>
    <title>gsd-2020-15094</title>
    <updated>2026-10-07T19:26:22.170417+00:00</updated>
    <content>gsd-2020-15094</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-15094"/>
  </entry>
</feed>
