<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:07:50.774810+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:20568</id>
    <title>ALSA-2026:20568 — Important: jmc security update</title>
    <updated>2026-10-02T22:07:51.370403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: jmc</p>
<p>JDK Mission Control is a powerful profiler for HotSpot JVMs and has an advanced set of tools that enables efficient and detailed analysis of the extensive data collected by JDK Flight Recorder. The tool chain enables developers and administrators to collect and analyze data from Java applications running locally or deployed in production environments.</p>
<p>Security Fix(es):</p>
<p>* lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing (CVE-2025-66566)
  * org.eclipse.jetty/jetty-[http:](http:) HTTP request smuggling via chunked extension quoted-string parsing (CVE-2026-2332)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:20568"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14791</id>
    <title>bdu:2026-14791</title>
    <updated>2026-10-02T22:07:51.370490+00:00</updated>
    <content>bdu:2026-14791</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14791"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</id>
    <title>certfr-2026-avi-0500 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
    <updated>2026-10-02T22:07:51.370514+00:00</updated>
    <content>certfr-2026-avi-0500</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-at59511</id>
    <title>Withdrawn: CLEANSTART-2026-AT59511 — Security fixes in cassandra-reaper-fips 4.0.2-r2</title>
    <updated>2026-10-02T22:07:51.370540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cassandra-reaper-fips</p>
<p>Package cassandra-reaper-fips version 4.0.2-r2 fixes 20 vulnerabilities: ghsa-r7wm-3cxj-wff9, ghsa-72hv-8253-57qq, CVE-2026-54512, CVE-2026-54513, CVE-2026-54514...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-at59511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-367736</id>
    <title>EUVD-2026-367736</title>
    <updated>2026-10-02T22:07:51.370584+00:00</updated>
    <content>EUVD-2026-367736</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-367736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2332</id>
    <title>fkie_cve-2026-2332</title>
    <updated>2026-10-02T22:07:51.370605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:
  *  https://w4ke.info/2025/06/18/funky-chunks.html</p>
<p>*  https://w4ke.info/2025/10/29/funky-chunks-2.html</p>
<p>Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error.</p>
<p>POST / HTTP/1.1
Host: localhost
Transfer-Encoding: chunked</p>
<p>1;ext="val
X
0</p>
<p>GET /smuggled HTTP/1.1
...</p>
<p>Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-2332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-355h-qmc2-wpwf</id>
    <title>GHSA-355h-qmc2-wpwf — Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing</title>
    <updated>2026-10-02T22:07:51.370659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.eclipse.jetty:jetty-http</p>
<p>### Description (as reported)</p>
<p>Jetty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks.</p>
<p>### Background</p>
<p>This vulnerability is a new variant discovered while researching the "Funky Chunks" HTTP request smuggling techniques:
- https://w4ke.info/2025/06/18/funky-chunks.html
- https://w4ke.info/2025/10/29/funky-chunks-2.html</p>
<p>The original research tested various chunk extension parsing differentials but did not test quoted-string handling within extension values.</p>
<p>### Technical Details</p>
<p>**RFC 9112 Section 7.1.1** defines chunked transfer encoding:
```
chunk = chunk-size [ chunk-ext ] CRLF chunk-data CRLF
chunk-ext = *( BWS ";" BWS chunk-ext-name [ BWS "=" BWS chunk-ext-val ] )
chunk-ext-val = token / quoted-string
```</p>
<p>**RFC 9110 Section 5.6.4** defines quoted-string:
```
quoted-string = DQUOTE *( qdtext / quoted-pair ) DQUOTE
```</p>
<p>A quoted-string continues until the closing DQUOTE, and `\r\n` sequences are not permitted within the quotes.</p>
<p>### Vulnerability</p>
<p>Jetty terminates chunk header parsing at `\r\n` inside quoted strings instead of treating this as an error.</p>
<p>**Expected (RFC compliant):**
```
Chunk: 1;a="value\r\nhere"\r\n
         ^^^^^^^^^^^^^^^^^^ extension value
Body: [1 byte after the real \r\n]
```</p>
<p>**Actual (jetty):**
```
Chunk: 1;a="value
            ^^^^^ terminates here (WRONG)
Body: here"... treated as body/next request
```</p>
<p>### Proof of Concept</p>
<p>```python
#!/usr/bin/env python3
import…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-355h-qmc2-wpwf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0169</id>
    <title>NCSC-2026-0169 — Kwetsbaarheden verholpen in Oracle Database Server</title>
    <updated>2026-10-02T22:07:51.370785+00:00</updated>
    <content>NCSC-2026-0169</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10574-1</id>
    <title>openSUSE-SU-2026:10574-1 — jetty-annotations-9.4.58-4.1 on GA media</title>
    <updated>2026-10-02T22:07:51.370836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jetty-annotations-9.4.58-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10574-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10175</id>
    <title>RHSA-2026:10175 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.27.1 Release.</title>
    <updated>2026-10-02T22:07:51.370873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10175"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:20568</id>
    <title>RLSA-2026:20568 — Important: jmc security update</title>
    <updated>2026-10-02T22:07:51.370996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: jmc</p>
<p>JDK Mission Control is a powerful profiler for HotSpot JVMs and has an advanced set of tools that enables efficient and detailed analysis of the extensive data collected by JDK Flight Recorder. The tool chain enables developers and administrators to collect and analyze data from Java applications running locally or deployed in production environments.</p>
<p>Security Fix(es):</p>
<p>* lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing (CVE-2025-66566)</p>
<p>* org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing (CVE-2026-2332)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:20568"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2332</id>
    <title>UBUNTU-CVE-2026-2332</title>
    <updated>2026-10-02T22:07:51.371057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: jetty9, Ubuntu:18.04:LTS: jetty9, Ubuntu:20.04:LTS: jetty9, Ubuntu:22.04:LTS: jetty9, Ubuntu:24.04:LTS: jetty9, Ubuntu:25.10: jetty9, Ubuntu:26.04:LTS: jetty12, Ubuntu:26.04:LTS: jetty9</p>
<p>In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:   *  https://w4ke.info/2025/06/18/funky-chunks.html   *  https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1082</id>
    <title>WID-SEC-W-2026-1082 — Eclipse Jetty: Schwachstelle ermöglicht Manipulation von Daten</title>
    <updated>2026-10-02T22:07:51.371128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Eclipse Jetty ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1082"/>
  </entry>
</feed>
