<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:11:41.896397+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05632</id>
    <title>bdu:2026-05632</title>
    <updated>2026-10-03T15:11:41.975283+00:00</updated>
    <content>bdu:2026-05632</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05632"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337331</id>
    <title>EUVD-2026-337331</title>
    <updated>2026-10-03T15:11:41.975327+00:00</updated>
    <content>EUVD-2026-337331</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337331"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33805</id>
    <title>fkie_cve-2026-33805</title>
    <updated>2026-10-03T15:11:41.975348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection header value. Any header added by the proxy for routing, access control, or security purposes can be selectively removed by a client. @fastify/http-proxy is also affected as it delegates to @fastify/reply-from.</p>
<p>Upgrade to @fastify/reply-from v12.6.2 or @fastify/http-proxy v11.4.4 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33805"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gwhp-pf74-vj37</id>
    <title>GHSA-gwhp-pf74-vj37 — Fastify's connection header abuse enables stripping of proxy-added headers</title>
    <updated>2026-10-03T15:11:41.975403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @fastify/reply-from, npm: @fastify/http-proxy</p>
<p>### Summary</p>
<p>`@fastify/reply-from` and `@fastify/http-proxy` process the client's `Connection` header after the proxy has added its own headers via `rewriteRequestHeaders`. This allows attackers to retroactively strip proxy-added headers (like access control or identification headers) from upstream requests by listing them in the `Connection` header value. This affects applications using these plugins with custom header injection for routing, access control, or security purposes.</p>
<p>### Details</p>
<p>The vulnerability exists in `@fastify/reply-from/lib/request.js` at lines 128-136 (HTTP/1.1 handler) and lines 191-200 (undici handler). The processing flow is:</p>
<p>1. Client headers are copied including the `connection` header (`@fastify/reply-from/index.js` line 91)
2. The proxy adds custom headers via `rewriteRequestHeaders` (line 151)
3. During request construction, the transport handlers read the client's `Connection` header and strip any headers listed in it
4. This stripping happens after `rewriteRequestHeaders`, allowing clients to target proxy-added headers for removal</p>
<p>RFC 7230 Section 6.1 Connection header processing is intended for proxies to strip hop-by-hop headers from incoming requests before adding their own headers. The current implementation reverses this order, processing the client's Connection header after the proxy has already modified the header set.</p>
<p>The call chain:
1. `@fastify/reply-from/index.js` line 91: `headers = { ...req.headers }` — copies ALL client heade…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gwhp-pf74-vj37"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10175</id>
    <title>RHSA-2026:10175 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.27.1 Release.</title>
    <updated>2026-10-03T15:11:41.975519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10175"/>
  </entry>
</feed>
