<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T03:58:08.196746+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-6140</id>
    <title>EUVD-2026-6140</title>
    <updated>2026-10-05T03:58:08.275712+00:00</updated>
    <content>EUVD-2026-6140</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-6140"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-39321</id>
    <title>fkie_cve-2024-39321</title>
    <updated>2026-10-05T03:58:08.275752+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes sent with spoofed IP addresses. Versions 2.11.6, 3.0.4, and 3.1.0-rc3 contain a patch for this issue. No known workarounds are available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-39321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gxrv-wf35-62w9</id>
    <title>GHSA-gxrv-wf35-62w9 — Bypassing IP allow-lists in traefik via HTTP/3 early data requests in QUIC 0-RTT handshakes</title>
    <updated>2026-10-05T03:58:08.275787+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3</p>
<p>### Impact</p>
<p>There is a vulnerability in Traefik that allows bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes sent with spoofed IP addresses.</p>
<p>### Patches</p>
<p>- https://github.com/traefik/traefik/releases/tag/v2.11.6
- https://github.com/traefik/traefik/releases/tag/v3.0.4
- https://github.com/traefik/traefik/releases/tag/v3.1.0-rc3</p>
<p>### Workarounds</p>
<p>No workaround.</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).</p>
<p>&lt;details&gt;
&lt;summary&gt;Original Description&lt;/summary&gt;
### Summary
Bypassing IP allow-lists in traefik via HTTP/3 early data requests in QUIC 0-RTT handshakes sent with spoofed IP addresses.</p>
<p>### Details
HTTP/3 supports sending HTTP requests as early data during QUIC 0-RTT handshakes to reduce RTT overhead for connection resumptions. Early data is sent and received before the handshake is completed and the client's IP address is validated.
The initial packet containing the QUIC 0-RTT handshake information and the early data HTTP request are sent as a single UDP datagram. Due to UDP being used by QUIC, the source IP address can be spoofed. When HTTP/3 servers process early data requests, the application layer only sees the unvalidated - possibly spoofed - IP address.</p>
<p>First, attackers have to obtain a session ticket from the HTTP/3 server. For that, attackers have to establish an HTTP/3 connection to the server - using their real IP address…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gxrv-wf35-62w9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14181-1</id>
    <title>openSUSE-SU-2024:14181-1 — traefik-3.0.4-2.1 on GA media</title>
    <updated>2026-10-05T03:58:08.275878+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>traefik-3.0.4-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14181-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:15847</id>
    <title>RHSA-2025:15847 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.23.0 Release.</title>
    <updated>2026-10-05T03:58:08.275897+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>hashicorp/consul: consul: Consul L7 Intentions Vulnerable To URL Path Bypass hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass quic-go: memory exhaustion attack against QUIC's connection ID mechanism golang: archive/zip: Incorrect handling of certain ZIP files traefik: denial of service traefik: Bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html cipher-base: Cipher-base hash manipulation sha.js: Missing type checks leading to hash rewind and passing on crafted data git: Git arbitrary file writes tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarball com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:15847"/>
  </entry>
</feed>
