<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:19:11.098158+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-09009</id>
    <title>bdu:2025-09009</title>
    <updated>2026-10-02T21:19:11.356621+00:00</updated>
    <content>bdu:2025-09009</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-09009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-38088</id>
    <title>EUVD-2026-38088</title>
    <updated>2026-10-02T21:19:11.356661+00:00</updated>
    <content>EUVD-2026-38088</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-38088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7663</id>
    <title>fkie_cve-2020-7663</title>
    <updated>2026-10-02T21:19:11.356676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-7663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g6wq-qcwm-j5g2</id>
    <title>GHSA-g6wq-qcwm-j5g2 — Regular Expression Denial of Service in websocket-extensions (RubyGem)</title>
    <updated>2026-10-02T21:19:11.356707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: websocket-extensions</p>
<p>### Impact</p>
<p>The ReDoS flaw allows an attacker to exhaust the server's capacity to process incoming requests by sending a WebSocket handshake request containing a header of the following form:</p>
<p>Sec-WebSocket-Extensions: a; b="\c\c\c\c\c\c\c\c\c\c ...</p>
<p>That is, a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. The parser takes exponential time to reject this header as invalid, and this will block the processing of any other work on the same thread. Thus if you are running a single-threaded server, such a request can render your service completely unavailable.</p>
<p>### Patches</p>
<p>Users should upgrade to version 0.1.5.</p>
<p>### Workarounds</p>
<p>There are no known work-arounds other than disabling any public-facing WebSocket functionality you are operating.</p>
<p>### References</p>
<p>- https://blog.jcoglan.com/2020/06/02/redos-vulnerability-in-websocket-extensions/</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g6wq-qcwm-j5g2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-7663</id>
    <title>gsd-2020-7663</title>
    <updated>2026-10-02T21:19:11.356745+00:00</updated>
    <content>gsd-2020-7663</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-7663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1553</id>
    <title>OESA-2022-1553 — rubygem-websocket-extensions security update</title>
    <updated>2026-10-02T21:19:11.356759+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: rubygem-websocket-extensions, openEuler:20.03-LTS-SP2: rubygem-websocket-extensions, openEuler:20.03-LTS-SP3: rubygem-websocket-extensions</p>
<p>Generic extension manager for WebSocket connections.

Security Fix(es):

websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.(CVE-2020-7663)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1553"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11357-1</id>
    <title>openSUSE-SU-2024:11357-1 — ruby2.7-rubygem-websocket-extensions-0.1.5-1.7 on GA media</title>
    <updated>2026-10-02T21:19:11.356786+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby2.7-rubygem-websocket-extensions-0.1.5-1.7 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11357-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:4366</id>
    <title>RHSA-2020:4366 — Red Hat Security Advisory: Satellite 6.8 release</title>
    <updated>2026-10-02T21:19:11.356803+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018) puppet-agent: Puppet Agent does not properly verify SSL connection when downloading a CRL rack-protection: Timing attack in authenticity_token.rb hibernate-validator: safeHTML validator allows XSS Django: Incorrect HTTP detection with reverse-proxy connecting via HTTPS rubygem-rack: hijack sessions by using timing attacks targeting the session id rubygem-secure_headers: limited header injection when using dynamic overrides with user input rubygem-secure_headers: directive injection when using dynamic overrides with user input rubygem-actionview: views that use the `j` or `escape_javascript` methods are susceptible to XSS attacks netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling rubygem-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser puppet: Arbitrary catalog retrieval puppet: puppet server and puppetDB may leak sensitive information via metrics API rubygem-rack: directory traversal in Rack::Directory rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie names jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core hibernate-validator: Improper input validation in the interpolation of constraint error messages jackson-databind: Ser…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:4366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:0127-1</id>
    <title>SUSE-SU-2023:0127-1 — Security update for rubygem-websocket-extensions</title>
    <updated>2026-10-02T21:19:11.356871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-websocket-extensions</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:0127-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7663</id>
    <title>UBUNTU-CVE-2020-7663</title>
    <updated>2026-10-02T21:19:11.356887+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: ruby-websocket-extensions, Ubuntu:18.04:LTS: ruby-websocket-extensions, Ubuntu:20.04:LTS: ruby-websocket-extensions</p>
<p>websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1087</id>
    <title>WID-SEC-W-2025-1087 — GitLab: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:19:11.356911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um einen Cross-Site Scripting oder Denial of Service Angriff durchzuführen, Sicherheitsmechanismen zu umgehen, Daten zu manipulieren oder vertrauliche Daten einzusehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1087"/>
  </entry>
</feed>
