<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:10:42.838940+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00183</id>
    <title>bdu:2024-00183</title>
    <updated>2026-10-03T17:10:42.992343+00:00</updated>
    <content>bdu:2024-00183</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0337</id>
    <title>certfr-2023-avi-0337 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
    <updated>2026-10-03T17:10:42.992383+00:00</updated>
    <content>certfr-2023-avi-0337</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232487</id>
    <title>EUVD-2026-232487</title>
    <updated>2026-10-03T17:10:42.992404+00:00</updated>
    <content>EUVD-2026-232487</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232487"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41915</id>
    <title>fkie_cve-2022-41915</title>
    <updated>2026-10-03T17:10:42.992417+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator&lt;?&gt;)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-41915"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hh82-3pmq-7frp</id>
    <title>GHSA-hh82-3pmq-7frp — Netty vulnerable to HTTP Response splitting from assigning header value iterator</title>
    <updated>2026-10-03T17:10:42.992451+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.netty:netty-codec-http</p>
<p>### Impact
When calling `DefaultHttpHeaders.set` with an _iterator_ of values (as opposed to a single given value), header value validation was not performed, allowing malicious header values in the iterator to perform [HTTP Response Splitting](https://owasp.org/www-community/attacks/HTTP_Response_Splitting).</p>
<p>### Patches
The necessary validation was added in Netty 4.1.86.Final.</p>
<p>### Workarounds
Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator&lt;?&gt;)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.</p>
<p>### References
[HTTP Response Splitting](https://owasp.org/www-community/attacks/HTTP_Response_Splitting)
[CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers](https://cwe.mitre.org/data/definitions/113.html)</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in [[example link to repo](https://github.com/netty/netty)](https://github.com/netty/netty)
* Email us at [netty-security@googlegroups.com](mailto:netty-security@googlegroups.com)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hh82-3pmq-7frp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-41915</id>
    <title>gsd-2022-41915</title>
    <updated>2026-10-03T17:10:42.992485+00:00</updated>
    <content>gsd-2022-41915</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-41915"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14442-1</id>
    <title>openSUSE-SU-2024:14442-1 — netty-4.1.114-1.1 on GA media</title>
    <updated>2026-10-03T17:10:42.992497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty-4.1.114-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14442-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:2096-2</id>
    <title>SUSE-SU-2023:2096-2 — Security update for netty, netty-tcnative</title>
    <updated>2026-10-03T17:10:42.992519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for netty, netty-tcnative</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:2096-2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41915</id>
    <title>UBUNTU-CVE-2022-41915</title>
    <updated>2026-10-03T17:10:42.992536+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: netty, Ubuntu:16.04:LTS: netty-3.9, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:18.04:LTS: netty-3.9, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty</p>
<p>Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator&lt;?&gt;)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41915"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0091</id>
    <title>WID-SEC-W-2023-0091 — NetApp ActiveIQ Unified Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:10:42.992567+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in NetApp ActiveIQ Unified Manager ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen und um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0091"/>
  </entry>
</feed>
