<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:31:14.555131+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:4791</id>
    <title>ALSA-2025:4791 — Moderate: python39:3.9 security update</title>
    <updated>2026-10-03T07:31:14.570767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python39, AlmaLinux:8: python39-PyMySQL, AlmaLinux:8: python39-cffi, AlmaLinux:8: python39-chardet, AlmaLinux:8: python39-cryptography, AlmaLinux:8: python39-devel, AlmaLinux:8: python39-idle, AlmaLinux:8: python39-idna, AlmaLinux:8: python39-libs, AlmaLinux:8: python39-lxml and 26 more</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* mod_wsgi: Trusted Proxy Headers Removing Bypass (CVE-2022-2255)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:4791"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05209</id>
    <title>bdu:2022-05209</title>
    <updated>2026-10-03T07:31:14.570911+00:00</updated>
    <content>bdu:2022-05209</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-mod_wsgi-2022-2255</id>
    <title>BIT-mod_wsgi-2022-2255</title>
    <updated>2026-10-03T07:31:14.570940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: mod_wsgi</p>
<p>A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-mod_wsgi-2022-2255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218</id>
    <title>certfr-2026-avi-0218 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T07:31:14.570976+00:00</updated>
    <content>certfr-2026-avi-0218</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-12290</id>
    <title>EUVD-2026-12290</title>
    <updated>2026-10-03T07:31:14.571004+00:00</updated>
    <content>EUVD-2026-12290</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-12290"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2255</id>
    <title>fkie_cve-2022-2255</title>
    <updated>2026-10-03T07:31:14.571026+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-2255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7527-8855-9cf8</id>
    <title>GHSA-7527-8855-9cf8 — Incorrect header handling in mod-wsgi</title>
    <updated>2026-10-03T07:31:14.571062+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mod-wsgi</p>
<p>A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7527-8855-9cf8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-2255</id>
    <title>gsd-2022-2255</title>
    <updated>2026-10-03T07:31:14.571096+00:00</updated>
    <content>gsd-2022-2255</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-2255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-2255</id>
    <title>msrc_CVE-2022-2255 — A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy all…</title>
    <updated>2026-10-03T07:31:14.571116+00:00</updated>
    <content>msrc_CVE-2022-2255</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-2255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1827</id>
    <title>OESA-2022-1827 — mod_wsgi security update</title>
    <updated>2026-10-03T07:31:14.571145+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: mod_wsgi, openEuler:20.03-LTS-SP3: mod_wsgi, openEuler:22.03-LTS: mod_wsgi</p>
<p>The mod_wsgi adapter is an Apache module that provides a WSGI compliant interface for hosting Python based web applications within Apache. The adapter is written completely in C code against the Apache C runtime andfor hosting WSGI applications within Apache has a lower overhead than using existing WSGI adapters for mod_python or CGI.

Security Fix(es):

A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy (trusted proxies are configured via the WSGITrustedProxies directive) allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.

References:
https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L13940-L13941
https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L14046-L14082(CVE-2022-2255)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1827"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12535-1</id>
    <title>openSUSE-SU-2024:12535-1 — apache2-mod_wsgi-4.9.4-1.1 on GA media</title>
    <updated>2026-10-03T07:31:14.571191+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache2-mod_wsgi-4.9.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12535-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2022-254</id>
    <title>PYSEC-2022-254</title>
    <updated>2026-10-03T07:31:14.571237+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mod-wsgi</p>
<p>A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2022-254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:4791</id>
    <title>RHSA-2025:4791 — Red Hat Security Advisory: python39:3.9 security update</title>
    <updated>2026-10-03T07:31:14.571272+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mod_wsgi: Trusted Proxy Headers Removing Bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:4791"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:4013-1</id>
    <title>SUSE-SU-2022:4013-1 — Security update for apache2-mod_wsgi</title>
    <updated>2026-10-03T07:31:14.571300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache2-mod_wsgi</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:4013-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2255</id>
    <title>UBUNTU-CVE-2022-2255</title>
    <updated>2026-10-03T07:31:14.571326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: mod-wsgi, Ubuntu:20.04:LTS: mod-wsgi, Ubuntu:22.04:LTS: mod-wsgi</p>
<p>A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2255"/>
  </entry>
</feed>
