<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:59:03.459747+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03688</id>
    <title>bdu:2021-03688</title>
    <updated>2026-10-02T12:59:03.485983+00:00</updated>
    <content>bdu:2021-03688</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03688"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-tomcat-2021-33037</id>
    <title>BIT-tomcat-2021-33037 — Incorrect Transfer-Encoding handling with HTTP/1.0</title>
    <updated>2026-10-02T12:59:03.486024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: tomcat</p>
<p>Apache Tomcat 10.0.0 to 10.0.6, 9.0.0 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-tomcat-2021-33037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-801</id>
    <title>certfr-2021-avi-801 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL.
Certaines d'entre elles permettent à un attaquant de…</title>
    <updated>2026-10-02T12:59:03.486062+00:00</updated>
    <content>certfr-2021-avi-801</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-28257</id>
    <title>EUVD-2026-28257</title>
    <updated>2026-10-02T12:59:03.486079+00:00</updated>
    <content>EUVD-2026-28257</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-28257"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-33037</id>
    <title>fkie_cve-2021-33037</title>
    <updated>2026-10-02T12:59:03.486090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-33037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4vww-mc66-62m6</id>
    <title>GHSA-4vww-mc66-62m6 — HTTP Request Smuggling in Apache Tomcat</title>
    <updated>2026-10-02T12:59:03.486114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat</p>
<p>Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4vww-mc66-62m6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-33037</id>
    <title>gsd-2021-33037</title>
    <updated>2026-10-02T12:59:03.486140+00:00</updated>
    <content>gsd-2021-33037</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-33037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1275</id>
    <title>OESA-2021-1275 — tomcat security update</title>
    <updated>2026-10-02T12:59:03.486151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: tomcat, openEuler:20.03-LTS-SP2: tomcat</p>
<p>The Apache Tomcat software is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. We invite you to participate in this open development project

Security Fix(es):

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.(CVE-2021-33037)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1490-1</id>
    <title>openSUSE-SU-2021:1490-1 — Security update for tomcat</title>
    <updated>2026-10-02T12:59:03.486177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1490-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:4861</id>
    <title>RHSA-2021:4861 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.6.0 Security release</title>
    <updated>2026-10-02T12:59:03.486195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: Read buffer overruns processing ASN.1 strings openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash() tomcat: JNDI realm authentication weakness tomcat: HTTP request smuggling when used with a reverse proxy tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:4861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:3602-1</id>
    <title>SUSE-SU-2021:3602-1 — Security update for tomcat</title>
    <updated>2026-10-02T12:59:03.486220+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:3602-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33037</id>
    <title>UBUNTU-CVE-2021-33037</title>
    <updated>2026-10-02T12:59:03.486235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: tomcat6, Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:20.04:LTS: tomcat9</p>
<p>Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</id>
    <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
    <updated>2026-10-02T12:59:03.486263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607"/>
  </entry>
</feed>
