<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T13:16:21.751912+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-07712</id>
    <title>bdu:2024-07712</title>
    <updated>2026-10-06T13:16:21.834164+00:00</updated>
    <content>bdu:2024-07712</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-07712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0812</id>
    <title>certfr-2024-avi-0812 — Une vulnérabilité a été découverte dans Traefik. Elle permet à un attaquant de provoquer un contournement de la politiq…</title>
    <updated>2026-10-06T13:16:21.834202+00:00</updated>
    <content>certfr-2024-avi-0812</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-186939</id>
    <title>EUVD-2026-186939</title>
    <updated>2026-10-06T13:16:21.834223+00:00</updated>
    <content>EUVD-2026-186939</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-186939"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45410</id>
    <title>fkie_cve-2024-45410</title>
    <updated>2026-10-06T13:16:21.834235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the request is routed to the application. For a HTTP client, it should not be possible to remove or modify these headers. Since the application trusts the value of these headers, security implications might arise, if they can be modified. For HTTP/1.1, however, it was found that some of theses custom headers can indeed be removed and in certain cases manipulated. The attack relies on the HTTP/1.1 behavior, that headers can be defined as hop-by-hop via the HTTP Connection header. This issue has been addressed in release versions 2.11.9 and 3.1.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-45410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-62c8-mh53-4cqv</id>
    <title>GHSA-62c8-mh53-4cqv — HTTP client can manipulate custom HTTP headers that are added by Traefik</title>
    <updated>2026-10-06T13:16:21.834276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/traefik/traefik/v3, Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik</p>
<p>### Impact</p>
<p>There is a vulnerability in Traefik that allows the client to remove the X-Forwarded headers (except the header X-Forwarded-For).</p>
<p>### Patches</p>
<p>- https://github.com/traefik/traefik/releases/tag/v2.11.9
- https://github.com/traefik/traefik/releases/tag/v3.1.3</p>
<p>### Workarounds</p>
<p>No workaround.</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).</p>
<p>&lt;details&gt;
&lt;summary&gt;Original Description&lt;/summary&gt;
### Summary</p>
<p>When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the request is routed to the application. For a HTTP client, it should not be possible to remove or modify these headers. Since the application trusts the value of these headers, security implications might arise, if they can be modified.</p>
<p>For HTTP/1.1, however, it was found that some of theses custom headers can indeed be removed and in certain cases manipulated. The attack relies on the HTTP/1.1 behavior, that headers can be defined as hop-by-hop via the HTTP Connection header. By setting the following connection header, the X-Forwarded-Host header can, for example, be removed:</p>
<p>Connection: close, X-Forwarded-Host</p>
<p>Depending on how the receiving application handles such cases, security implications may arise. Moreover, some application frameworks (e.g. Django) first transform the "-" to "_" signs, making it possible for the H…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-62c8-mh53-4cqv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14365-1</id>
    <title>openSUSE-SU-2024:14365-1 — traefik-3.1.4-1.1 on GA media</title>
    <updated>2026-10-06T13:16:21.834353+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>traefik-3.1.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14365-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:8244</id>
    <title>RHSA-2025:8244 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.21.0 release</title>
    <updated>2026-10-06T13:16:21.834372+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tar-fs: link following and path traversal via maliciously crafted tar file golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto traefik: HTTP client can manipulate custom HTTP headers that are added by Traefik golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:8244"/>
  </entry>
</feed>
