<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:22:50.379420+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00996</id>
    <title>bdu:2024-00996</title>
    <updated>2026-10-03T22:22:50.976965+00:00</updated>
    <content>bdu:2024-00996</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00996"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-airshare-cve-2024-23829</id>
    <title>BREW-airshare-CVE-2024-23829 — aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators</title>
    <updated>2026-10-03T22:22:50.977012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: airshare</p>
<p>### Summary
Security-sensitive parts of the *Python HTTP parser* retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.</p>
<p>### Details
These problems are rooted in pattern matching protocol elements, previously improved by PR #3235 and GHSA-gfw2-4jvh-wgfg:</p>
<p>1. The expression `HTTP/(\d).(\d)` lacked another backslash to clarify that the separator should be a literal dot, not just *any* Unicode code point (result: `HTTP/(\d)\.(\d)`).</p>
<p>2. The HTTP version was permitting Unicode digits, where only ASCII digits are standards-compliant.</p>
<p>3. Distinct regular expressions for validating HTTP Method and Header field names were used - though both should (at least) apply the common restrictions of rfc9110 `token`.</p>
<p>### PoC
`GET / HTTP/1ö1`
`GET / HTTP/1.𝟙`
`GET/: HTTP/1.1`
`Content-Encoding?: chunked`</p>
<p>### Impact
Primarily concerns running an aiohttp server without llhttp:
 1. **behind a proxy**: Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling.
 2. **directly accessible** or exposed behind proxies relaying malformed input: the unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities.</p>
<p>-----…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-airshare-cve-2024-23829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199</id>
    <title>certfr-2024-avi-0199 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-03T22:22:50.977096+00:00</updated>
    <content>certfr-2024-avi-0199</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258104</id>
    <title>EUVD-2026-258104</title>
    <updated>2026-10-03T22:22:50.977116+00:00</updated>
    <content>EUVD-2026-258104</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258104"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23829</id>
    <title>fkie_cve-2024-23829</title>
    <updated>2026-10-03T22:22:50.977128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.  Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-23829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8qpw-xqxj-h4r2</id>
    <title>GHSA-8qpw-xqxj-h4r2 — aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators</title>
    <updated>2026-10-03T22:22:50.977154+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiohttp</p>
<p>### Summary
Security-sensitive parts of the *Python HTTP parser* retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.</p>
<p>### Details
These problems are rooted in pattern matching protocol elements, previously improved by PR #3235 and GHSA-gfw2-4jvh-wgfg:</p>
<p>1. The expression `HTTP/(\d).(\d)` lacked another backslash to clarify that the separator should be a literal dot, not just *any* Unicode code point (result: `HTTP/(\d)\.(\d)`).</p>
<p>2. The HTTP version was permitting Unicode digits, where only ASCII digits are standards-compliant.</p>
<p>3. Distinct regular expressions for validating HTTP Method and Header field names were used - though both should (at least) apply the common restrictions of rfc9110 `token`.</p>
<p>### PoC
`GET / HTTP/1ö1`
`GET / HTTP/1.𝟙`
`GET/: HTTP/1.1`
`Content-Encoding?: chunked`</p>
<p>### Impact
Primarily concerns running an aiohttp server without llhttp:
 1. **behind a proxy**: Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling.
 2. **directly accessible** or exposed behind proxies relaying malformed input: the unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities.</p>
<p>-----…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8qpw-xqxj-h4r2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-23829</id>
    <title>gsd-2024-23829</title>
    <updated>2026-10-03T22:22:50.977210+00:00</updated>
    <content>gsd-2024-23829</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-23829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-23829</id>
    <title>msrc_CVE-2024-23829 — aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators</title>
    <updated>2026-10-03T22:22:50.977223+00:00</updated>
    <content>msrc_CVE-2024-23829</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-23829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1250</id>
    <title>OESA-2025-1250 — python-aiohttp security update</title>
    <updated>2026-10-03T22:22:50.977240+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: python-aiohttp</p>
<p>Async http client/server framework (asyncio).

Security Fix(es):</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.(CVE-2023-47627)</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method. The vulnerability occurs only if the attacker can control the HTTP method (GET, POST etc.) of the request. If the attacker can control the HTTP version of the request it will be able to modify the request (request smuggling). This issue has been patched in version 3.9.0.(CVE-2023-49082)</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option &amp;apos;follow_symlinks&amp;apos; can be used to determine whether to follow symbolic links outside the static root directory. When &amp;apos;follow_symlinks&amp;apos; is set to…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2024-26</id>
    <title>PYSEC-2024-26</title>
    <updated>2026-10-03T22:22:50.977307+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiohttp</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.  Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2024-26"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1536</id>
    <title>RHSA-2024:1536 — Red Hat Security Advisory: Satellite 6.14.3 Async Security Update</title>
    <updated>2026-10-03T22:22:50.977332+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Hub: insecure galaxy-importer tarfile extraction python-django: Denial-of-service possibility in django.utils.text.Truncator python-aiohttp: numerous issues in HTTP parser with header parsing aiohttp: HTTP request modification jinja2: HTML attribute injection when passing user input as keys to xmlattr filter aiohttp: follow_symlinks directory traversal vulnerability python-aiohttp: http request smuggling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23829</id>
    <title>UBUNTU-CVE-2024-23829</title>
    <updated>2026-10-03T22:22:50.977359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp, Ubuntu:Pro:24.04:LTS: python-aiohttp</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.  Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0949</id>
    <title>WID-SEC-W-2024-0949 — Red Hat Satellite: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:22:50.977383+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, HTTP-Request-Smuggling-Angriffe durchzuführen oder Phishing- und Cross-Site-Scripting (XSS)-Angriffe auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0949"/>
  </entry>
</feed>
