<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:55:51.941709+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-04601</id>
    <title>bdu:2021-04601</title>
    <updated>2026-10-03T21:55:51.994603+00:00</updated>
    <content>bdu:2021-04601</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-04601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-352</id>
    <title>certfr-2021-avi-352 — De multiples vulnérabilités ont été découvertes dans Ruby-on-rails.
Elles permettent à un attaquant de provoquer un dén…</title>
    <updated>2026-10-03T21:55:51.994642+00:00</updated>
    <content>certfr-2021-avi-352</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-352"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-23210</id>
    <title>EUVD-2026-23210</title>
    <updated>2026-10-03T21:55:51.994662+00:00</updated>
    <content>EUVD-2026-23210</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-23210"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22902</id>
    <title>fkie_cve-2021-22902</title>
    <updated>2026-10-03T21:55:51.994674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-22902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g8ww-46x2-2p65</id>
    <title>GHSA-g8ww-46x2-2p65 — Denial of Service in Action Dispatch</title>
    <updated>2026-10-03T21:55:51.994706+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionpack</p>
<p>Impact
------
There is a possible Denial of Service vulnerability in Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.</p>
<p>Releases
--------
The fixed releases are available at the normal locations.</p>
<p>Workarounds
-----------
The following monkey patch placed in an initializer can be used to work around the issue.</p>
<p>```ruby
module Mime
  class Type
    MIME_REGEXP = /\A(?:\*\/\*|#{MIME_NAME}\/(?:\*|#{MIME_NAME})(?&gt;\s*#{MIME_PARAMETER}\s*)*)\z/
  end
end
```</p>
<p>Patches
-------
To aid users who aren't able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.</p>
<p>* 6-0-Prevent-catastrophic-backtracking-during-mime-parsin.patch - Patch for 6.0 series
* 6-1-Prevent-catastrophic-backtracking-during-mime-parsin.patch - Patch for 6.1 series</p>
<p>Please note that only the 6.1.Z, 6.0.Z, and 5.2.Z series are supported at present. Users of earlier unsupported releases are advised to upgrade as soon as possible as we cannot guarantee the continued availability of security fixes for unsupported releases.</p>
<p>Credits
-------</p>
<p>Thanks to Security Curious &lt;security...@pm.me&gt; for reporting this!</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g8ww-46x2-2p65"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-22902</id>
    <title>gsd-2021-22902</title>
    <updated>2026-10-03T21:55:51.994744+00:00</updated>
    <content>gsd-2021-22902</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-22902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11318-1</id>
    <title>openSUSE-SU-2024:11318-1 — ruby2.7-rubygem-actionpack-6.0-6.0.4-1.2 on GA media</title>
    <updated>2026-10-03T21:55:51.994756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby2.7-rubygem-actionpack-6.0-6.0.4-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11318-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:4702</id>
    <title>RHSA-2021:4702 — Red Hat Security Advisory: Satellite 6.10 Release</title>
    <updated>2026-10-03T21:55:51.994777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-ecdsa: Unexpected and  undocumented exceptions during signature decoding python-ecdsa: DER encoding is not being verified in signatures rubygem-activerecord-session_store: hijack sessions by using timing attacks targeting the session id rake: OS Command Injection via egrep in Rake::FileList guava: local information disclosure via temporary directory created with unsafe permissions PyYAML: incomplete fix for CVE-2020-1747 rubygem-nokogiri: XML external entity injection via Nokogiri::XML::Schema Satellite: Azure compute resource secret_key leak to authenticated users foreman: possible man-in-the-middle in smart_proxy realm_freeipa Satellite: BMC controller credential leak via API python-aiohttp: Open redirect in aiohttp.web_middlewares.normalize_path_middleware rubygem-actionpack: Possible Information Disclosure / Unintended Method Execution in Action Pack rails: Possible Denial of Service vulnerability in Action Dispatch rails: Possible DoS Vulnerability in Action Controller Token Authentication django: potential directory-traversal via uploaded files rubygem-puma: incomplete fix for CVE-2019-16770 allows Denial of Service (DoS) django: Potential directory-traversal via uploaded files rubygem-addressable: ReDoS in templates django: Potential directory traversal via ``admindocs`` python-urllib3: ReDoS in the parsing of authority part of URL django: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:4702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22902</id>
    <title>UBUNTU-CVE-2021-22902</title>
    <updated>2026-10-03T21:55:51.994819+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails</p>
<p>The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0341</id>
    <title>WID-SEC-W-2022-0341 — Ruby on Rails: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:55:51.994849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um Informationen offenzulegen, einen Denial of Service Zustand auszulösen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0341"/>
  </entry>
</feed>
