<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:26:35.181693+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-06308</id>
    <title>bdu:2024-06308</title>
    <updated>2026-10-03T13:26:35.404348+00:00</updated>
    <content>bdu:2024-06308</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-06308"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0512</id>
    <title>certfr-2025-avi-0512 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T13:26:35.404387+00:00</updated>
    <content>certfr-2025-avi-0512</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0512"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255086</id>
    <title>EUVD-2026-255086</title>
    <updated>2026-10-03T13:26:35.404407+00:00</updated>
    <content>EUVD-2026-255086</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-6827</id>
    <title>fkie_cve-2024-6827</title>
    <updated>2026-10-03T13:26:35.404418+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-6827"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hc5x-x2vx-497g</id>
    <title>GHSA-hc5x-x2vx-497g — Gunicorn HTTP Request/Response Smuggling vulnerability</title>
    <updated>2026-10-03T13:26:35.404449+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gunicorn</p>
<p>Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hc5x-x2vx-497g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3657</id>
    <title>OESA-2026-3657 — python-gunicorn security update</title>
    <updated>2026-10-03T13:26:35.404473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: python-gunicorn</p>
<p>Gunicorn(Green Unicorn) is a Python WSGI HTTP Server for UNIX. It&amp;amp;apos;s a pre-fork worker model ported from Ruby&amp;amp;apos;s Unicorn_ project. The Gunicorn server is broadly compatible with various web frameworks, simply implemented, light on server resource usage, and fairly speedy.

Security Fix(es):</p>
<p>Gunicorn version 21.2.0 does not properly validate the value of the &amp;apos;Transfer-Encoding&amp;apos; header as specified in the RFC standards, which leads to the default fallback method of &amp;apos;Content-Length,&amp;apos; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.(CVE-2024-6827)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3657"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1433</id>
    <title>PYSEC-2026-1433 — Gunicorn HTTP Request/Response Smuggling vulnerability</title>
    <updated>2026-10-03T13:26:35.404499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gunicorn</p>
<p>Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:3651</id>
    <title>RHBA-2025:3651 — Red Hat Bug Fix Advisory: Red Hat Quay v3.13.5 bug fix release</title>
    <updated>2026-10-03T13:26:35.404519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gunicorn: HTTP Request Smuggling in benoitc/gunicorn golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh jinja2: Jinja sandbox breakout through attr filter selecting format method</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:3651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6827</id>
    <title>UBUNTU-CVE-2024-6827</title>
    <updated>2026-10-03T13:26:35.404540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: gunicorn, Ubuntu:16.04:LTS: gunicorn, Ubuntu:18.04:LTS: gunicorn, Ubuntu:20.04:LTS: gunicorn, Ubuntu:22.04:LTS: gunicorn, Ubuntu:24.04:LTS: gunicorn, Ubuntu:25.10: gunicorn, Ubuntu:26.04:LTS: gunicorn</p>
<p>Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6827"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0998</id>
    <title>WID-SEC-W-2025-0998 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:26:35.404586+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren, vertrauliche Informationen preiszugeben und einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0998"/>
  </entry>
</feed>
