<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:01:50.019460+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:10987</id>
    <title>ALSA-2024:10987 — Moderate: pcs security update</title>
    <updated>2026-10-04T01:01:50.182012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: pcs, AlmaLinux:8: pcs-snmp</p>
<p>The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.</p>
<p>Security Fix(es):</p>
<p>* sinatra: Open Redirect Vulnerability in Sinatra via X-Forwarded-Host Header (CVE-2024-21510)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:10987"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03808</id>
    <title>bdu:2025-03808</title>
    <updated>2026-10-04T01:01:50.182076+00:00</updated>
    <content>bdu:2025-03808</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2024-21510</id>
    <title>BREW-mailcatcher-CVE-2024-21510 — Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision</title>
    <updated>2026-10-04T01:01:50.182093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: mailcatcher</p>
<p>Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2024-21510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</id>
    <title>certfr-2025-avi-0967 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-04T01:01:50.182117+00:00</updated>
    <content>certfr-2025-avi-0967</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-202275</id>
    <title>EUVD-2026-202275</title>
    <updated>2026-10-04T01:01:50.182133+00:00</updated>
    <content>EUVD-2026-202275</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-202275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-21510</id>
    <title>fkie_cve-2024-21510</title>
    <updated>2026-10-04T01:01:50.182143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-21510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hxx2-7vcw-mqr3</id>
    <title>GHSA-hxx2-7vcw-mqr3 — Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision</title>
    <updated>2026-10-04T01:01:50.182165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: sinatra</p>
<p>Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hxx2-7vcw-mqr3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-21510</id>
    <title>gsd-2024-21510</title>
    <updated>2026-10-04T01:01:50.182185+00:00</updated>
    <content>gsd-2024-21510</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-21510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:10987</id>
    <title>RHSA-2024:10987 — Red Hat Security Advisory: pcs security update</title>
    <updated>2026-10-04T01:01:50.182196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sinatra: Open Redirect Vulnerability in Sinatra via X-Forwarded-Host Header</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:10987"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21510</id>
    <title>UBUNTU-CVE-2024-21510</title>
    <updated>2026-10-04T01:01:50.182211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ruby-sinatra, Ubuntu:Pro:18.04:LTS: ruby-sinatra, Ubuntu:Pro:20.04:LTS: ruby-sinatra, Ubuntu:22.04:LTS: ruby-sinatra, Ubuntu:24.04:LTS: ruby-sinatra</p>
<p>Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21510"/>
  </entry>
</feed>
