<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:05:36.031927+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-07501</id>
    <title>bdu:2022-07501</title>
    <updated>2026-10-03T04:05:36.304619+00:00</updated>
    <content>bdu:2022-07501</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-07501"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-tomcat-2022-42252</id>
    <title>BIT-tomcat-2022-42252 — Apache Tomcat request smuggling via malformed content-length</title>
    <updated>2026-10-03T04:05:36.304662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: tomcat</p>
<p>If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0 to 9.0.67, 10.0.0 to 10.0.26 or 10.1.0 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-tomcat-2022-42252"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-975</id>
    <title>certfr-2022-avi-975 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un
attaquant de provoquer un contournement de la p…</title>
    <updated>2026-10-03T04:05:36.304696+00:00</updated>
    <content>certfr-2022-avi-975</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-975"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ag86451</id>
    <title>Withdrawn: CLEANSTART-2026-AG86451 — Security fixes in tomcat9 9.0.68-r0</title>
    <updated>2026-10-03T04:05:36.304713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: tomcat9</p>
<p>Package tomcat9 version 9.0.68-r0 fixes 1 vulnerabilities: CVE-2022-42252</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ag86451"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-237886</id>
    <title>EUVD-2026-237886</title>
    <updated>2026-10-03T04:05:36.304734+00:00</updated>
    <content>EUVD-2026-237886</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-237886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-42252</id>
    <title>fkie_cve-2022-42252</title>
    <updated>2026-10-03T04:05:36.304746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-42252"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p22x-g9px-3945</id>
    <title>GHSA-p22x-g9px-3945 — Apache Tomcat may reject request containing invalid Content-Length header</title>
    <updated>2026-10-03T04:05:36.304767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.apache.tomcat:tomcat-coyote</p>
<p>If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p22x-g9px-3945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-42252</id>
    <title>gsd-2022-42252</title>
    <updated>2026-10-03T04:05:36.304796+00:00</updated>
    <content>gsd-2022-42252</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-42252"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1058</id>
    <title>OESA-2023-1058 — tomcat security update</title>
    <updated>2026-10-03T04:05:36.304807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: tomcat, openEuler:20.03-LTS-SP3: tomcat, openEuler:22.03-LTS: tomcat, openEuler:22.03-LTS-SP1: tomcat</p>
<p>The Apache Tomcat software is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. We invite you to participate in this open development project

Security Fix(es):

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.(CVE-2022-42252)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12534-1</id>
    <title>openSUSE-SU-2024:12534-1 — tomcat-9.0.43-11.1 on GA media</title>
    <updated>2026-10-03T04:05:36.304835+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat-9.0.43-11.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12534-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:1663</id>
    <title>RHSA-2023:1663 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.2 release and security update</title>
    <updated>2026-10-03T04:05:36.304853+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: request smuggling tomcat: JsonErrorReportValve injection</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:1663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:4193-1</id>
    <title>SUSE-SU-2022:4193-1 — Security update for tomcat</title>
    <updated>2026-10-03T04:05:36.304870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:4193-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-42252</id>
    <title>UBUNTU-CVE-2022-42252</title>
    <updated>2026-10-03T04:05:36.304894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9</p>
<p>If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-42252"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1918</id>
    <title>WID-SEC-W-2022-1918 — Apache Tomcat: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T04:05:36.304922+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1918"/>
  </entry>
</feed>
