<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:21:21.872473+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1029</id>
    <title>certfr-2024-avi-1029 — Une vulnérabilité a été découverte dans Traefik. Elle permet à un attaquant de provoquer un contournement de la politiq…</title>
    <updated>2026-10-04T10:21:21.875670+00:00</updated>
    <content>certfr-2024-avi-1029</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-1029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-205252</id>
    <title>EUVD-2026-205252</title>
    <updated>2026-10-04T10:21:21.875718+00:00</updated>
    <content>EUVD-2026-205252</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-205252"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-52003</id>
    <title>fkie_cve-2024-52003</title>
    <updated>2026-10-04T10:21:21.875733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-52003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h924-8g65-j9wg</id>
    <title>GHSA-h924-8g65-j9wg — Traefik's X-Forwarded-Prefix Header still allows for Open Redirect</title>
    <updated>2026-10-04T10:21:21.875760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3</p>
<p>### Impact</p>
<p>There is a vulnerability in Traefik that allows the client to provide the `X-Forwarded-Prefix` header from an untrusted source.</p>
<p>### Patches</p>
<p>- https://github.com/traefik/traefik/releases/tag/v2.11.14
- https://github.com/traefik/traefik/releases/tag/v3.2.1</p>
<p>### Workarounds</p>
<p>No workaround.</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).</p>
<p>&lt;details&gt;
&lt;summary&gt;Original Description&lt;/summary&gt;
### Summary
The previously reported open redirect ([GHSA-6qq8-5wq3-86rp](https://github.com/traefik/traefik/security/advisories/GHSA-6qq8-5wq3-86rp)) is not fixed correctly. The safePrefix function can be tricked to return an absolute URL.</p>
<p>### Details
The Traefik API [dashboard component](https://github.com/traefik/traefik/blob/master/pkg/api/dashboard/dashboard.go) tries to validate that the value of the header X-Forwarded-Prefix is a site relative path:
```go
http.Redirect(resp, req, safePrefix(req)+"/dashboard/", http.StatusFound)
```</p>
<p>```go
func safePrefix(req *http.Request) string {
	prefix := req.Header.Get("X-Forwarded-Prefix")
	if prefix == "" {
		return ""
	}</p>
<p>parse, err := url.Parse(prefix)
	if err != nil {
		return ""
	}</p>
<p>return parse.Path
}
```</p>
<p>### PoC
An attacker can bypass this by sending the following payload:</p>
<p>```bash
curl -v 'http://traefik.localhost' -H 'X-Forwarded-Prefix: %0d//a.com'
[...]
&gt; HTTP/1.1 302 Found
&gt; Location: //a.com/dashboard/
```</p>
<p>or sim…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h924-8g65-j9wg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14567-1</id>
    <title>openSUSE-SU-2024:14567-1 — govulncheck-vulndb-0.0.20241209T183251-1.1 on GA media</title>
    <updated>2026-10-04T10:21:21.875813+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20241209T183251-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14567-1"/>
  </entry>
</feed>
