<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:50:04.901952+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10615</id>
    <title>bdu:2025-10615</title>
    <updated>2026-10-03T23:50:05.072738+00:00</updated>
    <content>bdu:2025-10615</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-serveit-cve-2024-47220</id>
    <title>BREW-serveit-CVE-2024-47220 — HTTP Request Smuggling in ruby webrick</title>
    <updated>2026-10-03T23:50:05.072789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: serveit</p>
<p>An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-serveit-cve-2024-47220"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0003</id>
    <title>certfr-2025-avi-0003 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T23:50:05.072839+00:00</updated>
    <content>certfr-2025-avi-0003</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47220</id>
    <title>fkie_cve-2024-47220</title>
    <updated>2026-10-03T23:50:05.072873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-47220"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6f62-3596-g6w7</id>
    <title>GHSA-6f62-3596-g6w7 — HTTP Request Smuggling in ruby webrick</title>
    <updated>2026-10-03T23:50:05.072899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: webrick</p>
<p>An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6f62-3596-g6w7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2226</id>
    <title>OESA-2024-2226 — rubygem-webrick security update</title>
    <updated>2026-10-03T23:50:05.072922+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: rubygem-webrick, openEuler:22.03-LTS-SP4: rubygem-webrick, openEuler:22.03-LTS-SP3: rubygem-webrick, openEuler:20.03-LTS-SP4: rubygem-webrick, openEuler:22.03-LTS-SP1: rubygem-webrick</p>
<p>WEBrick is an HTTP server toolkit that can be configured as an HTTPS server, a proxy server, and a virtual-host server.

Security Fix(es):

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., &amp;quot;GET /admin HTTP/1.1\r\n&amp;quot; inside of a &amp;quot;POST /user HTTP/1.1\r\n&amp;quot; request. NOTE: the supplier&amp;apos;s position is &amp;quot;Webrick should not be used in production.&amp;quot;(CVE-2024-47220)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2226"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:1227</id>
    <title>RHSA-2025:1227 — Red Hat Security Advisory: Logging for Red Hat OpenShift - 5.9.11</title>
    <updated>2026-10-03T23:50:05.072952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rsync: Info Leak via Uninitialized Stack Contents WEBrick: HTTP request smuggling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:1227"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3939-1</id>
    <title>SUSE-SU-2024:3939-1 — Security update for ruby2.1</title>
    <updated>2026-10-03T23:50:05.072972+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ruby2.1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3939-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47220</id>
    <title>UBUNTU-CVE-2024-47220</title>
    <updated>2026-10-03T23:50:05.072987+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:22.04:LTS: ruby-webrick, Ubuntu:24.04:LTS: ruby-webrick, Ubuntu:25.10: ruby-webrick</p>
<p>Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47220"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0001</id>
    <title>WID-SEC-W-2025-0001 — IBM DB2: Mehrere Schwachstellen</title>
    <updated>2026-10-03T23:50:05.073012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter oder lokaler Angreifer kann mehrere Schwachstellen in IBM DB2 on Cloud Pak for Data ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu erzeugen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0001"/>
  </entry>
</feed>
