<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:22:58.681219+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02173</id>
    <title>bdu:2024-02173</title>
    <updated>2026-10-03T22:22:59.176468+00:00</updated>
    <content>bdu:2024-02173</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-airshare-cve-2023-47627</id>
    <title>BREW-airshare-CVE-2023-47627 — AIOHTTP has problems in HTTP parser (the python one, not llhttp)</title>
    <updated>2026-10-03T22:22:59.176527+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: airshare</p>
<p># Summary
The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling.
This parser is only used when `AIOHTTP_NO_EXTENSIONS` is enabled (or not using a prebuilt wheel).
 
# Details</p>
<p>## Bug 1: Bad parsing of `Content-Length` values</p>
<p>### Description
RFC 9110 says this:
&gt; `Content-Length = 1*DIGIT`</p>
<p>AIOHTTP does not enforce this rule, presumably because of an incorrect usage of the builtin `int` constructor. Because the `int` constructor accepts `+` and `-` prefixes, and digit-separating underscores, using `int` to parse CL values leads AIOHTTP to significant misinterpretation.</p>
<p>### Examples
```
GET / HTTP/1.1\r\n
Content-Length: -0\r\n
\r\n
X
```
```
GET / HTTP/1.1\r\n
Content-Length: +0_1\r\n
\r\n
X
```</p>
<p>### Suggested action
Verify that a `Content-Length` value consists only of ASCII digits before parsing, as the standard requires.</p>
<p>## Bug 2: Improper handling of NUL, CR, and LF in header values</p>
<p>### Description
RFC 9110 says this:
&gt; Field values containing CR, LF, or NUL characters are invalid and dangerous, due to the varying ways that implementations might parse and interpret those characters; a recipient of CR, LF, or NUL within a field value MUST either reject the message or replace each of those characters with SP before further processing or forwarding of that message.</p>
<p>AIOHTTP's HTTP parser does not enforce this rule, and will happily process header values containing these three forbidden characters without replacing the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-airshare-cve-2023-47627"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</id>
    <title>certfr-2024-avi-0145 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-03T22:22:59.176592+00:00</updated>
    <content>certfr-2024-avi-0145</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258094</id>
    <title>EUVD-2026-258094</title>
    <updated>2026-10-03T22:22:59.176612+00:00</updated>
    <content>EUVD-2026-258094</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-47627</id>
    <title>fkie_cve-2023-47627</title>
    <updated>2026-10-03T22:22:59.176624+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-47627"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gfw2-4jvh-wgfg</id>
    <title>GHSA-gfw2-4jvh-wgfg — AIOHTTP has problems in HTTP parser (the python one, not llhttp)</title>
    <updated>2026-10-03T22:22:59.176647+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiohttp</p>
<p># Summary
The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling.
This parser is only used when `AIOHTTP_NO_EXTENSIONS` is enabled (or not using a prebuilt wheel).
 
# Details</p>
<p>## Bug 1: Bad parsing of `Content-Length` values</p>
<p>### Description
RFC 9110 says this:
&gt; `Content-Length = 1*DIGIT`</p>
<p>AIOHTTP does not enforce this rule, presumably because of an incorrect usage of the builtin `int` constructor. Because the `int` constructor accepts `+` and `-` prefixes, and digit-separating underscores, using `int` to parse CL values leads AIOHTTP to significant misinterpretation.</p>
<p>### Examples
```
GET / HTTP/1.1\r\n
Content-Length: -0\r\n
\r\n
X
```
```
GET / HTTP/1.1\r\n
Content-Length: +0_1\r\n
\r\n
X
```</p>
<p>### Suggested action
Verify that a `Content-Length` value consists only of ASCII digits before parsing, as the standard requires.</p>
<p>## Bug 2: Improper handling of NUL, CR, and LF in header values</p>
<p>### Description
RFC 9110 says this:
&gt; Field values containing CR, LF, or NUL characters are invalid and dangerous, due to the varying ways that implementations might parse and interpret those characters; a recipient of CR, LF, or NUL within a field value MUST either reject the message or replace each of those characters with SP before further processing or forwarding of that message.</p>
<p>AIOHTTP's HTTP parser does not enforce this rule, and will happily process header values containing these three forbidden characters without replacing the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gfw2-4jvh-wgfg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-47627</id>
    <title>gsd-2023-47627</title>
    <updated>2026-10-03T22:22:59.176690+00:00</updated>
    <content>gsd-2023-47627</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-47627"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-47627</id>
    <title>msrc_CVE-2023-47627 — Request smuggling in aiohttp</title>
    <updated>2026-10-03T22:22:59.176702+00:00</updated>
    <content>msrc_CVE-2023-47627</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-47627"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1250</id>
    <title>OESA-2025-1250 — python-aiohttp security update</title>
    <updated>2026-10-03T22:22:59.176719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: python-aiohttp</p>
<p>Async http client/server framework (asyncio).

Security Fix(es):</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.(CVE-2023-47627)</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method. The vulnerability occurs only if the attacker can control the HTTP method (GET, POST etc.) of the request. If the attacker can control the HTTP version of the request it will be able to modify the request (request smuggling). This issue has been patched in version 3.9.0.(CVE-2023-49082)</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option &amp;apos;follow_symlinks&amp;apos; can be used to determine whether to follow symbolic links outside the static root directory. When &amp;apos;follow_symlinks&amp;apos; is set to…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13465-1</id>
    <title>openSUSE-SU-2024:13465-1 — python310-aiohttp-3.9.0-1.1 on GA media</title>
    <updated>2026-10-03T22:22:59.176760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-aiohttp-3.9.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13465-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2023-246</id>
    <title>PYSEC-2023-246</title>
    <updated>2026-10-03T22:22:59.176777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiohttp</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2023-246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1057</id>
    <title>RHSA-2024:1057 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update</title>
    <updated>2026-10-03T22:22:59.176797+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pygments: ReDoS in pygments python-pillow: uncontrolled resource consumption when textlength in an ImageDraw instance operates on a long text argument python-aiohttp: numerous issues in HTTP parser with header parsing aiohttp: HTTP request modification aiohttp: CRLF injection if user controls the HTTP method using aiohttp client pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex platform: Insecure websocket used when interacting with EDA server jinja2: HTML attribute injection when passing user input as keys to xmlattr filter Django: denial-of-service in ``intcomma`` template filter</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-47627</id>
    <title>UBUNTU-CVE-2023-47627</title>
    <updated>2026-10-03T22:22:59.176828+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-47627"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0522</id>
    <title>WID-SEC-W-2024-0522 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:22:59.176849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, Phishing-Angriffe durchzuführen oder Cross-Site Scripting (XSS)-Angriffe auszuführen. Einige dieser Schwachstellen erfordern eine Benutzerinteraktion, um sie erfolgreich auszunutzen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0522"/>
  </entry>
</feed>
