<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:27:15.697746+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03458</id>
    <title>bdu:2025-03458</title>
    <updated>2026-10-02T15:27:16.135787+00:00</updated>
    <content>bdu:2025-03458</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03458"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-airshare-cve-2024-27306</id>
    <title>BREW-airshare-CVE-2024-27306 — aiohttp Cross-site Scripting vulnerability on index pages for static file handling</title>
    <updated>2026-10-02T15:27:16.135834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: airshare</p>
<p>### Summary</p>
<p>A XSS vulnerability exists on index pages for static file handling.</p>
<p>### Details</p>
<p>When using `web.static(..., show_index=True)`, the resulting index pages do not escape file names.</p>
<p>If users can upload files with arbitrary filenames to the static directory, the server is vulnerable to XSS attacks.</p>
<p>### Workaround</p>
<p>We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected.</p>
<p>Other users can disable `show_index` if unable to upgrade.</p>
<p>-----</p>
<p>Patch: https://github.com/aio-libs/aiohttp/pull/8319/files</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-airshare-cve-2024-27306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0514</id>
    <title>certfr-2024-avi-0514 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T15:27:16.135903+00:00</updated>
    <content>certfr-2024-avi-0514</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258109</id>
    <title>EUVD-2026-258109</title>
    <updated>2026-10-02T15:27:16.135931+00:00</updated>
    <content>EUVD-2026-258109</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258109"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27306</id>
    <title>fkie_cve-2024-27306</title>
    <updated>2026-10-02T15:27:16.135950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-27306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7gpw-8wmc-pm8g</id>
    <title>GHSA-7gpw-8wmc-pm8g — aiohttp Cross-site Scripting vulnerability on index pages for static file handling</title>
    <updated>2026-10-02T15:27:16.135988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiohttp</p>
<p>### Summary</p>
<p>A XSS vulnerability exists on index pages for static file handling.</p>
<p>### Details</p>
<p>When using `web.static(..., show_index=True)`, the resulting index pages do not escape file names.</p>
<p>If users can upload files with arbitrary filenames to the static directory, the server is vulnerable to XSS attacks.</p>
<p>### Workaround</p>
<p>We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected.</p>
<p>Other users can disable `show_index` if unable to upgrade.</p>
<p>-----</p>
<p>Patch: https://github.com/aio-libs/aiohttp/pull/8319/files</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7gpw-8wmc-pm8g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-27306</id>
    <title>gsd-2024-27306</title>
    <updated>2026-10-02T15:27:16.136042+00:00</updated>
    <content>gsd-2024-27306</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-27306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-27306</id>
    <title>msrc_CVE-2024-27306 — aiohttp vulnerable to XSS on index pages for static file handling</title>
    <updated>2026-10-02T15:27:16.136060+00:00</updated>
    <content>msrc_CVE-2024-27306</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-27306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1250</id>
    <title>OESA-2025-1250 — python-aiohttp security update</title>
    <updated>2026-10-02T15:27:16.136085+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: python-aiohttp</p>
<p>Async http client/server framework (asyncio).

Security Fix(es):</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.(CVE-2023-47627)</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method. The vulnerability occurs only if the attacker can control the HTTP method (GET, POST etc.) of the request. If the attacker can control the HTTP version of the request it will be able to modify the request (request smuggling). This issue has been patched in version 3.9.0.(CVE-2023-49082)</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option &amp;apos;follow_symlinks&amp;apos; can be used to determine whether to follow symbolic links outside the static root directory. When &amp;apos;follow_symlinks&amp;apos; is set to…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13965-1</id>
    <title>openSUSE-SU-2024:13965-1 — python310-aiohttp-3.9.5-2.1 on GA media</title>
    <updated>2026-10-02T15:27:16.136194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-aiohttp-3.9.5-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13965-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1102</id>
    <title>PYSEC-2026-1102 — aiohttp Cross-site Scripting vulnerability on index pages for static file handling</title>
    <updated>2026-10-02T15:27:16.136220+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiohttp</p>
<p>### Summary</p>
<p>A XSS vulnerability exists on index pages for static file handling.</p>
<p>### Details</p>
<p>When using `web.static(..., show_index=True)`, the resulting index pages do not escape file names.</p>
<p>If users can upload files with arbitrary filenames to the static directory, the server is vulnerable to XSS attacks.</p>
<p>### Workaround</p>
<p>We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected.</p>
<p>Other users can disable `show_index` if unable to upgrade.</p>
<p>-----</p>
<p>Patch: https://github.com/aio-libs/aiohttp/pull/8319/files</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:3781</id>
    <title>RHSA-2024:3781 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update</title>
    <updated>2026-10-02T15:27:16.136273+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pip: Mercurial configuration injectable in repo revision when installing via pip golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm python-cryptography: NULL-dereference when loading PKCS7 certificates pillow: Arbitrary Code Execution via the environment parameter python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-Encoding headers python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode() python-pydantic: regular expression denial of service via crafted email string sqlparse: parsing heavily nested list leads to denial of service psf/black: ReDoS via the lines_with_leading_tabs_expanded() function in strings.py file golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm python-cryptography: NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override aiohttp: XSS on index pages for static file handling python-django: Potential regular expression denial-of-service in django.utils.text.Truncator.words() python-pillow: buffer overflow in _imagingcms.c follow-redirects: Possible credential leak aiohttp: DoS when trying to parse malformed POST requests python-social-auth: Improper Handling of Case Sensitivity in social-auth-app-django jinja2: accept…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:3781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27306</id>
    <title>UBUNTU-CVE-2024-27306</title>
    <updated>2026-10-02T15:27:16.136367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp, Ubuntu:Pro:24.04:LTS: python-aiohttp</p>
<p>aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1328</id>
    <title>WID-SEC-W-2024-1328 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:27:16.136392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand erzeugen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren oder Cross-Site-Scripting (XSS)-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1328"/>
  </entry>
</feed>
