<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:06:21.087247+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-02449</id>
    <title>bdu:2023-02449</title>
    <updated>2026-10-02T15:06:21.281883+00:00</updated>
    <content>bdu:2023-02449</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-02449"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2023-23934</id>
    <title>BREW-aws-sam-cli-CVE-2023-23934 — Incorrect parsing of nameless cookies leads to __Host- cookies bypass</title>
    <updated>2026-10-02T15:06:21.281927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aws-sam-cli</p>
<p>Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like `=__Host-test=bad` for another subdomain.</p>
<p>Werkzeug &lt;= 2.2.2 will parse the cookie `=__Host-test=bad` as `__Host-test=bad`. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2023-23934"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0427</id>
    <title>certfr-2023-avi-0427 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T15:06:21.281966+00:00</updated>
    <content>certfr-2023-avi-0427</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-221567</id>
    <title>EUVD-2026-221567</title>
    <updated>2026-10-02T15:06:21.281984+00:00</updated>
    <content>EUVD-2026-221567</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-221567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-23934</id>
    <title>fkie_cve-2023-23934</title>
    <updated>2026-10-02T15:06:21.281996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like `=__Host-test=bad` for another subdomain. Werkzeug prior to 2.2.3 will parse the cookie `=__Host-test=bad` as __Host-test=bad`. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key. The issue is fixed in Werkzeug 2.2.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-23934"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-px8h-6qxv-m22q</id>
    <title>GHSA-px8h-6qxv-m22q — Incorrect parsing of nameless cookies leads to __Host- cookies bypass</title>
    <updated>2026-10-02T15:06:21.282021+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Werkzeug</p>
<p>Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like `=__Host-test=bad` for another subdomain.</p>
<p>Werkzeug &lt;= 2.2.2 will parse the cookie `=__Host-test=bad` as `__Host-test=bad`. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-px8h-6qxv-m22q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-23934</id>
    <title>gsd-2023-23934</title>
    <updated>2026-10-02T15:06:21.282046+00:00</updated>
    <content>gsd-2023-23934</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-23934"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-046-11</id>
    <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
    <updated>2026-10-02T15:06:21.282057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.</p>
<p>This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-046-11"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-23934</id>
    <title>msrc_CVE-2023-23934 — Wrkzeug's incorrect parsing of nameless cookies leads to __Host- cookies bypass</title>
    <updated>2026-10-02T15:06:21.282469+00:00</updated>
    <content>msrc_CVE-2023-23934</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-23934"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1515</id>
    <title>OESA-2023-1515 — python-werkzeug security update</title>
    <updated>2026-10-02T15:06:21.282486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: python-werkzeug, openEuler:20.03-LTS-SP3: python-werkzeug, openEuler:22.03-LTS: python-werkzeug, openEuler:22.03-LTS-SP1: python-werkzeug, openEuler:22.03-LTS-SP2: python-werkzeug</p>
<p>*werkzeug* German noun: "tool". Etymology: *werk* ("work"), *zeug* ("stuff") Werkzeug is a comprehensive `WSGI`_ web application library. It began as a simple collection of various utilities for WSGI applications and has become one of the most advanced WSGI utility libraries. It includes:
-   An interactive debugger that allows inspecting stack traces and source code in the browser with an interactive interpreter for any frame in the stack. -   A full-featured request object with objects to interact with headers, query args, form data, files, and cookies. -   A response object that can wrap other WSGI applications and handle streaming data. -   A routing system for matching URLs to endpoints and generating URLs for endpoints, with an extensible system for capturing variables from URLs. -   HTTP utilities to handle entity tags, cache control, dates, user agents, cookies, files, and more. -   A threaded WSGI server for use while developing applications locally. -   A test client for simulating HTTP requests during testing without requiring running a server. Werkzeug doesn't enforce any dependencies. It is up to the developer to choose a template engine, database adapter, and even how to handle requests. It can be used to build all sorts of end user applications
such as blogs, wikis, or bulletin boards. `Flask`_ wraps Werkzeug, using it to handle the details of WSGI while providing more structure and patterns for defining powerful applications.</p>
<p>Security Fix(es):</p>
<p>Werkzeug is a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2023-57</id>
    <title>PYSEC-2023-57</title>
    <updated>2026-10-02T15:06:21.282533+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: werkzeug</p>
<p>Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like `=__Host-test=bad` for another subdomain. Werkzeug prior to 2.2.3 will parse the cookie `=__Host-test=bad` as __Host-test=bad`. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key. The issue is fixed in Werkzeug 2.2.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2023-57"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:1018</id>
    <title>RHSA-2023:1018 — Red Hat Security Advisory: Red Hat OpenStack Platform 17.0 (python-werkzeug) security update</title>
    <updated>2026-10-02T15:06:21.282556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-werkzeug: cookie prefixed with = can shadow unprefixed cookie python-werkzeug: high resource usage when parsing multipart form data with many fields</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:1018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-23934</id>
    <title>UBUNTU-CVE-2023-23934</title>
    <updated>2026-10-02T15:06:21.282575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-werkzeug, Ubuntu:18.04:LTS: python-werkzeug, Ubuntu:20.04:LTS: python-werkzeug, Ubuntu:22.04:LTS: python-werkzeug</p>
<p>Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like `=__Host-test=bad` for another subdomain. Werkzeug prior to 2.2.3 will parse the cookie `=__Host-test=bad` as __Host-test=bad`. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key. The issue is fixed in Werkzeug 2.2.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-23934"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1497</id>
    <title>WID-SEC-W-2023-1497 — IBM Spectrum Protect: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:06:21.282600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect ausnutzen, um einen Denial of Service Angriff durchzuführen, Dateien zu manipulieren oder Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1497"/>
  </entry>
</feed>
