<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:21:26.327501+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-01344</id>
    <title>bdu:2021-01344</title>
    <updated>2026-10-04T06:21:26.752711+00:00</updated>
    <content>bdu:2021-01344</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-01344"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2020-8184</id>
    <title>BREW-mailcatcher-CVE-2020-8184 — Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names</title>
    <updated>2026-10-04T06:21:26.752757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: mailcatcher</p>
<p>A reliance on cookies without validation/integrity check security vulnerability exists in rack &lt; 2.2.3, rack &lt; 2.1.4 that makes it possible for an attacker to forge a secure or host-only cookie prefix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2020-8184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-52838</id>
    <title>cnvd-2020-52838</title>
    <updated>2026-10-04T06:21:26.752794+00:00</updated>
    <content>cnvd-2020-52838</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-52838"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-38303</id>
    <title>EUVD-2026-38303</title>
    <updated>2026-10-04T06:21:26.752808+00:00</updated>
    <content>EUVD-2026-38303</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-38303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8184</id>
    <title>fkie_cve-2020-8184</title>
    <updated>2026-10-04T06:21:26.752819+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A reliance on cookies without validation/integrity check security vulnerability exists in rack &lt; 2.2.3, rack &lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-8184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j6w9-fv6q-3q52</id>
    <title>GHSA-j6w9-fv6q-3q52 — Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names</title>
    <updated>2026-10-04T06:21:26.752840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: rack</p>
<p>A reliance on cookies without validation/integrity check security vulnerability exists in rack &lt; 2.2.3, rack &lt; 2.1.4 that makes it possible for an attacker to forge a secure or host-only cookie prefix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j6w9-fv6q-3q52"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-8184</id>
    <title>gsd-2020-8184</title>
    <updated>2026-10-04T06:21:26.752861+00:00</updated>
    <content>gsd-2020-8184</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-8184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1729</id>
    <title>OESA-2022-1729 — rubygem-rack security update</title>
    <updated>2026-10-04T06:21:26.752873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: rubygem-rack, openEuler:20.03-LTS-SP3: rubygem-rack, openEuler:22.03-LTS: rubygem-rack</p>
<p>Rack provides a minimal, modular, and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers,  web frameworks, and software in between (the so-called middleware) into  a single method call.

Security Fix(es):

Denial of Service Vulnerability in Rack Multipart Parsing(CVE-2022-30122)

Possible shell escape sequence injection vulnerability in Rack(CVE-2022-30123)

A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;lt; 2.2.3, rack &amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.(CVE-2020-8184)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1993-1</id>
    <title>openSUSE-SU-2020:1993-1 — Security update for rmt-server</title>
    <updated>2026-10-04T06:21:26.752900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rmt-server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1993-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:4366</id>
    <title>RHSA-2020:4366 — Red Hat Security Advisory: Satellite 6.8 release</title>
    <updated>2026-10-04T06:21:26.752926+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018) puppet-agent: Puppet Agent does not properly verify SSL connection when downloading a CRL rack-protection: Timing attack in authenticity_token.rb hibernate-validator: safeHTML validator allows XSS Django: Incorrect HTTP detection with reverse-proxy connecting via HTTPS rubygem-rack: hijack sessions by using timing attacks targeting the session id rubygem-secure_headers: limited header injection when using dynamic overrides with user input rubygem-secure_headers: directive injection when using dynamic overrides with user input rubygem-actionview: views that use the `j` or `escape_javascript` methods are susceptible to XSS attacks netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling rubygem-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser puppet: Arbitrary catalog retrieval puppet: puppet server and puppetDB may leak sensitive information via metrics API rubygem-rack: directory traversal in Rack::Directory rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie names jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core hibernate-validator: Improper input validation in the interpolation of constraint error messages jackson-databind: Ser…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:4366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:2678-1</id>
    <title>SUSE-SU-2020:2678-1 — Security update for rubygem-rack</title>
    <updated>2026-10-04T06:21:26.752993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-rack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:2678-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8184</id>
    <title>UBUNTU-CVE-2020-8184</title>
    <updated>2026-10-04T06:21:26.753009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ruby-rack, Ubuntu:16.04:LTS: ruby-rack, Ubuntu:18.04:LTS: ruby-rack, Ubuntu:20.04:LTS: ruby-rack</p>
<p>A reliance on cookies without validation/integrity check security vulnerability exists in rack &lt; 2.2.3, rack &lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8184"/>
  </entry>
</feed>
