<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:41:21.217011+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-kafka-2020-27218</id>
    <title>BIT-kafka-2020-27218</title>
    <updated>2026-10-04T07:41:21.432072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: kafka</p>
<p>In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-kafka-2020-27218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-951</id>
    <title>certfr-2021-avi-951 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-04T07:41:21.432139+00:00</updated>
    <content>certfr-2021-avi-951</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-951"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-46430</id>
    <title>EUVD-2026-46430</title>
    <updated>2026-10-04T07:41:21.432161+00:00</updated>
    <content>EUVD-2026-46430</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-46430"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-27218</id>
    <title>fkie_cve-2020-27218</title>
    <updated>2026-10-04T07:41:21.432174+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-27218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-86wm-rrjm-8wh8</id>
    <title>GHSA-86wm-rrjm-8wh8 — Buffer not correctly recycled in Gzip Request inflation</title>
    <updated>2026-10-04T07:41:21.432228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.eclipse.jetty:jetty-server</p>
<p>### Impact
If GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection and if an 
attacker can send a request with a body that is received entirely by not consumed by the application, then a subsequent request
on the same connection will see that body prepended to it's body.</p>
<p>The attacker will not see any data, but may inject data into the body of the subsequent request</p>
<p>CVE score is [4.8 AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L&amp;version=3.1)</p>
<p>### Workarounds
The problem can be worked around by either:
- Disabling compressed request body inflation by GzipHandler.
- By always fully consuming the request content before sending a response.
- By adding a `Connection: close` to any response where the servlet does not fully consume request content.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-86wm-rrjm-8wh8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-27218</id>
    <title>gsd-2020-27218</title>
    <updated>2026-10-04T07:41:21.432271+00:00</updated>
    <content>gsd-2020-27218</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-27218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0012-1</id>
    <title>openSUSE-SU-2021:0012-1 — Security update for jetty-minimal</title>
    <updated>2026-10-04T07:41:21.432283+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jetty-minimal</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0012-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2021:2854</id>
    <title>RHBA-2021:2854 — Red Hat Bug Fix Advisory: Migration Toolkit for Containers (MTC) 1.4.6 release advisory</title>
    <updated>2026-10-04T07:41:21.432300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libwebp: heap-based buffer overflow in PutLE16() nss: TLS 1.3 CCS flood remote DoS Attack openldap: NULL pointer dereference for unauthenticated packet in slapd kernel: security bypass in certs/blacklist.c and certs/system_keyring.c jetty: local temporary directory hijacking vulnerability jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS libwebp: heap-based buffer overflow in WebPDecode*Into functions libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c lz4: memory corruption due to an integer overflow bug caused by memmove argument libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms rpm: Signature checks bypass via corrupted rpm package jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnera…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2021:2854"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:3922-1</id>
    <title>SUSE-SU-2020:3922-1 — Security update for jetty-minimal</title>
    <updated>2026-10-04T07:41:21.432356+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jetty-minimal</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:3922-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-27218</id>
    <title>UBUNTU-CVE-2020-27218</title>
    <updated>2026-10-04T07:41:21.432372+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: jetty, Ubuntu:16.04:LTS: eclipse, Ubuntu:16.04:LTS: jetty, Ubuntu:18.04:LTS: eclipse</p>
<p>In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-27218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2783</id>
    <title>WID-SEC-W-2023-2783 — Eclipse Jetty: Schwachstelle ermöglicht Manipulation</title>
    <updated>2026-10-04T07:41:21.432396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Eclipse Jetty ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2783"/>
  </entry>
</feed>
