<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T03:10:21.882492+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-103087</id>
    <title>cnvd-2021-103087</title>
    <updated>2026-10-05T03:10:21.948209+00:00</updated>
    <content>cnvd-2021-103087</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-103087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-32653</id>
    <title>EUVD-2026-32653</title>
    <updated>2026-10-05T03:10:21.948247+00:00</updated>
    <content>EUVD-2026-32653</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-32653"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43795</id>
    <title>fkie_cve-2021-43795</title>
    <updated>2026-10-05T03:10:21.948262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation logic. Armeria 1.13.4 or above contains the hardened path validation logic that handles `%2F` properly. This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-43795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8fp4-rp6c-5gcv</id>
    <title>GHSA-8fp4-rp6c-5gcv — Path Traversal in com.linecorp.armeria:armeria</title>
    <updated>2026-10-05T03:10:21.948302+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.linecorp.armeria:armeria</p>
<p>### Impact</p>
<p>An attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation logic.</p>
<p>### Patches</p>
<p>Armeria 1.13.4 or above contains the hardened path validation logic that handles `%2F` properly.</p>
<p>### Workarounds</p>
<p>This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path, e.g.</p>
<p>```java
Server
  .builder()
  .serviceUnder(
    "/files",
    FileService
      .of(...)
      .decorate((delegate, ctx, req) -&gt; {
        String path = req.headers().path();
        if (path.contains("%2f") || path.contains("%2F")) {
          return HttpResponse.of(HttpStatus.BAD_REQUEST);
        }
        return delegate.serve(ctx, req);
      })
  )
  .build()
```</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:
* Open an issue in [line/armeria](https://github.com/line/armeria)
* Chat with us at [Slack](https://armeria.dev/s/slack)</p>
<p>### Credits</p>
<p>This vulnerability was originally reported by Abdallah Zaher ([elcayser-0x0a](https://hackerone.com/elcayser-0x0a?type=user)).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8fp4-rp6c-5gcv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-43795</id>
    <title>gsd-2021-43795</title>
    <updated>2026-10-05T03:10:21.948344+00:00</updated>
    <content>gsd-2021-43795</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-43795"/>
  </entry>
</feed>
