<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:18:31.322490+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01632</id>
    <title>bdu:2026-01632</title>
    <updated>2026-10-03T05:18:31.605445+00:00</updated>
    <content>bdu:2026-01632</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01632"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0029</id>
    <title>certfr-2026-avi-0029 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu Gemfire. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-03T05:18:31.605484+00:00</updated>
    <content>certfr-2026-avi-0029</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-aj02810</id>
    <title>Withdrawn: CLEANSTART-2026-AJ02810 — Security fixes in kserve-modelmesh 0.12.0-r0</title>
    <updated>2026-10-03T05:18:31.605504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: kserve-modelmesh</p>
<p>Package kserve-modelmesh version 0.12.0-r0 fixes 20 vulnerabilities: CVE-2026-24281, CVE-2026-24308, CVE-2026-33870, CVE-2026-33871, ghsa-7xrh-hqfc-g7qr...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-aj02810"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-263615</id>
    <title>EUVD-2026-263615</title>
    <updated>2026-10-03T05:18:31.605534+00:00</updated>
    <content>EUVD-2026-263615</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-263615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-67735</id>
    <title>fkie_cve-2025-67735</title>
    <updated>2026-10-03T05:18:31.605546+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-67735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-84h7-rjj3-6jx4</id>
    <title>GHSA-84h7-rjj3-6jx4 — Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder</title>
    <updated>2026-10-03T05:18:31.605569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.netty:netty-codec-http</p>
<p>### Summary</p>
<p>The `io.netty.handler.codec.http.HttpRequestEncoder` CRLF injection with the request uri when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the uri.</p>
<p>### Details</p>
<p>The `HttpRequestEncoder` simply UTF8 encodes the `uri` without sanitization (`buf.writeByte(SP).writeCharSequence(uriCharSequence, CharsetUtil.UTF_8);`)</p>
<p>The default implementation of HTTP headers guards against such possibility already with a validator making it impossible with headers.</p>
<p>### PoC</p>
<p>Simple reproducer:</p>
<p>```java
public static void main(String[] args) {</p>
<p>EmbeddedChannel client = new EmbeddedChannel();
  client.pipeline().addLast(new HttpClientCodec());</p>
<p>EmbeddedChannel server = new EmbeddedChannel();
  server.pipeline().addLast(new HttpServerCodec());
  server.pipeline().addLast(new ChannelInboundHandlerAdapter() {
    @Override
    public void channelRead(ChannelHandlerContext ctx, Object msg) throws Exception {
      System.out.println("Processing msg " + msg);
    }
  });</p>
<p>DefaultHttpRequest request = new DefaultHttpRequest(
    HttpVersion.HTTP_1_1,
    HttpMethod.GET,
    "/s1 HTTP/1.1\r\n" +
      "\r\n" +
      "POST /s2 HTTP/1.1\r\n" +
      "content-length: 11\r\n\r\n" +
      "Hello World" +
      "GET /s1"
  );
  client.writeAndFlush(request);
  ByteBuf tmp;
  while ((tmp = client.readOutbound()) != null) {
    server.writeInbound(tmp);
  }
}
```</p>
<p>### Impact</p>
<p>Any application / framework using `HttpRe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-84h7-rjj3-6jx4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0021</id>
    <title>NCSC-2026-0021 — Kwetsbaarheden verholpen in Oracle Database Server producten</title>
    <updated>2026-10-03T05:18:31.605614+00:00</updated>
    <content>NCSC-2026-0021</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15824-1</id>
    <title>openSUSE-SU-2025:15824-1 — netty-4.1.130-1.1 on GA media</title>
    <updated>2026-10-03T05:18:31.605654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty-4.1.130-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15824-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:1899</id>
    <title>RHSA-2026:1899 — Red Hat Security Advisory: Red Hat build of Quarkus 3.20.5 release and security update</title>
    <updated>2026-10-03T05:18:31.605670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ongres-scram: Timing Attack Vulnerability in SCRAM Authentication io.quarkus/quarkus-rest: Quarkus REST Worker Thread Exhaustion Vulnerability netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:1899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:4489-1</id>
    <title>SUSE-SU-2025:4489-1 — Security update for netty</title>
    <updated>2026-10-03T05:18:31.605689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for netty</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:4489-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-67735</id>
    <title>UBUNTU-CVE-2025-67735</title>
    <updated>2026-10-03T05:18:31.605703+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:24.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:25.10: netty</p>
<p>Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-67735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0157</id>
    <title>WID-SEC-W-2026-0157 — Oracle Database Server: Mehrere Schwachstellen</title>
    <updated>2026-10-03T05:18:31.605736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Database Server ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0157"/>
  </entry>
</feed>
