<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:42:33.032955+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09579</id>
    <title>bdu:2026-09579</title>
    <updated>2026-10-03T10:42:33.765627+00:00</updated>
    <content>bdu:2026-09579</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-34525</id>
    <title>BREW-aider-CVE-2026-34525 — AIOHTTP accepts duplicate Host headers</title>
    <updated>2026-10-03T10:42:33.765678+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aider</p>
<p>### Summary</p>
<p>Multiple Host headers were allowed in aiohttp.</p>
<p>### Impact</p>
<p>Mostly this doesn't affect aiohttp security itself, but if a reverse proxy is applying security rules depending on the target Host, it is theoretically possible that the proxy and aiohttp could process different host names, possibly resulting in bypassing a security check on the proxy and getting a request processed by aiohttp in a privileged sub app when using `Application.add_domain()`.</p>
<p>-----</p>
<p>Patch: https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349
Patch: https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-34525"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0550</id>
    <title>certfr-2026-avi-0550 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T10:42:33.765740+00:00</updated>
    <content>certfr-2026-avi-0550</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0550"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-an24336</id>
    <title>Withdrawn: CLEANSTART-2026-AN24336 — Security fixes for CVE-2024-12797, CVE-2024-52303, CVE-2024-52304, CVE-2024-56201, CVE-2024-56326, CVE-2025-24023, CVE-…</title>
    <updated>2026-10-03T10:42:33.765766+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: airflow-2</p>
<p>Multiple security vulnerabilities affect the airflow-2 package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-an24336"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329293</id>
    <title>EUVD-2026-329293</title>
    <updated>2026-10-03T10:42:33.765820+00:00</updated>
    <content>EUVD-2026-329293</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329293"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34525</id>
    <title>fkie_cve-2026-34525</title>
    <updated>2026-10-03T10:42:33.765841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34525"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c427-h43c-vf67</id>
    <title>GHSA-c427-h43c-vf67 — AIOHTTP accepts duplicate Host headers</title>
    <updated>2026-10-03T10:42:33.765872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiohttp</p>
<p>### Summary</p>
<p>Multiple Host headers were allowed in aiohttp.</p>
<p>### Impact</p>
<p>Mostly this doesn't affect aiohttp security itself, but if a reverse proxy is applying security rules depending on the target Host, it is theoretically possible that the proxy and aiohttp could process different host names, possibly resulting in bypassing a security check on the proxy and getting a request processed by aiohttp in a privileged sub app when using `Application.add_domain()`.</p>
<p>-----</p>
<p>Patch: https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349
Patch: https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c427-h43c-vf67"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2192</id>
    <title>OESA-2026-2192 — python-aiohttp security update</title>
    <updated>2026-10-03T10:42:33.765913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-aiohttp</p>
<p>Async http client/server framework (asyncio).

Security Fix(es):</p>
<p>Insufficient restrictions in header/trailer handling could cause uncapped memory usage.(CVE-2026-22815)</p>
<p>An unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation.(CVE-2026-34513)</p>
<p>An attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits.(CVE-2026-34514)</p>
<p>A response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability.(CVE-2026-34516)</p>
<p>For some multipart form fields, aiohttp read the entire field into memory before checking client_max_size.(CVE-2026-34517)</p>
<p>When following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers.(CVE-2026-34518)</p>
<p>aiohttp is vulnerable to HTTP response splitting attacks. An attacker can insert carriage return (\r) characters in the reason phrase to craft malicious responses, leading to response splitting attacks. This vulnerability affects aiohttp versions up to and including 3.13.3.(CVE-2026-34519)</p>
<p>The llhttp parser in aiohttp accepts null bytes and control characters in response header values, which could allow attackers to perform HTTP header injection attacks and bypass security restrictions.(CVE-2026-34520)</p>
<p>aiohttp is a Python asynchronous HTTP client/server framework. In version 3.13.3 and earlier, there is a sec…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2192"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21098-1</id>
    <title>openSUSE-SU-2026:21098-1 — Security update for python-aiohttp</title>
    <updated>2026-10-03T10:42:33.765976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-aiohttp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21098-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2103</id>
    <title>PYSEC-2026-2103</title>
    <updated>2026-10-03T10:42:33.766010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiohttp</p>
<p>AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22173-1</id>
    <title>SUSE-SU-2026:22173-1 — Security update for python-aiohttp</title>
    <updated>2026-10-03T10:42:33.766038+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-aiohttp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22173-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34525</id>
    <title>UBUNTU-CVE-2026-34525</title>
    <updated>2026-10-03T10:42:33.766069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-aiohttp, Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:20.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp, Ubuntu:Pro:24.04:LTS: python-aiohttp, Ubuntu:25.10: python-aiohttp, Ubuntu:Pro:26.04:LTS: python-aiohttp</p>
<p>AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34525"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</id>
    <title>WID-SEC-W-2026-2933 — Splunk SOAR: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:42:33.766113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933"/>
  </entry>
</feed>
