<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:32:33.201332+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351613</id>
    <title>EUVD-2026-351613</title>
    <updated>2026-10-02T14:32:33.363038+00:00</updated>
    <content>EUVD-2026-351613</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351613"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-12382</id>
    <title>fkie_cve-2026-12382</title>
    <updated>2026-10-02T14:32:33.363083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-12382"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-45w6-c976-v24q</id>
    <title>GHSA-45w6-c976-v24q</title>
    <updated>2026-10-02T14:32:33.363117+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-45w6-c976-v24q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13508</id>
    <title>RHSA-2026:13508 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update</title>
    <updated>2026-10-02T14:32:33.363136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Django: Django: Denial of Service via crafted request with duplicate headers python-markdown: denial of service via malformed HTML-like sequences aap-controller: aap-gateway: Account hijacking and unauthorized access via unverified email linking aap-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID net/url: Incorrect parsing of IPv6 host literals in net/url minimatch: minimatch: Denial of Service via specially crafted glob patterns pyOpenSSL: DTLS cookie callback buffer overflow rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13508"/>
  </entry>
</feed>
