<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:31:31.976567+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09230</id>
    <title>bdu:2026-09230</title>
    <updated>2026-10-02T23:31:32.100601+00:00</updated>
    <content>bdu:2026-09230</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09230"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-travis-cve-2026-34835</id>
    <title>BREW-travis-CVE-2026-34835 — Rack::Request accepts invalid Host characters, enabling host allowlist bypass</title>
    <updated>2026-10-02T23:31:32.100641+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: travis</p>
<p>## Summary</p>
<p>`Rack::Request` parses the `Host` header using an `AUTHORITY` regular expression that accepts characters not permitted in RFC-compliant hostnames, including `/`, `?`, `#`, and `@`. Because `req.host` returns the full parsed value, applications that validate hosts using naive prefix or suffix checks can be bypassed.</p>
<p>For example, a check such as `req.host.start_with?("myapp.com")` can be bypassed with `Host: myapp.com@evil.com`, and a check such as `req.host.end_with?("myapp.com")` can be bypassed with `Host: evil.com/myapp.com`.</p>
<p>This can lead to host header poisoning in applications that use `req.host`, `req.url`, or `req.base_url` for link generation, redirects, or origin validation.</p>
<p>## Details</p>
<p>`Rack::Request` parses the authority component using logic equivalent to:</p>
<p>```ruby
AUTHORITY = /
  \A
  (?&lt;host&gt;
    \[(?&lt;address&gt;#{ipv6})\]
    |
    (?&lt;address&gt;[[[:graph:]&amp;&amp;[^\[\]]]]*?)
  )
  (:(?&lt;port&gt;\d+))?
  \z
/x
```</p>
<p>The character class used for non-IPv6 hosts accepts nearly all printable characters except `[` and `]`. This includes reserved URI delimiters such as `@`, `/`, `?`, and `#`, which are not valid hostname characters under RFC 3986 host syntax.</p>
<p>As a result, values such as the following are accepted and returned through `req.host`:</p>
<p>```text
myapp.com@evil.com
evil.com/myapp.com
evil.com#myapp.com
```</p>
<p>Applications that attempt to allowlist hosts using string prefix or suffix checks may therefore treat attacker-controlled hosts as trusted. For example:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-travis-cve-2026-34835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278841</id>
    <title>EUVD-2026-278841</title>
    <updated>2026-10-02T23:31:32.100701+00:00</updated>
    <content>EUVD-2026-278841</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34835</id>
    <title>fkie_cve-2026-34835</title>
    <updated>2026-10-02T23:31:32.100716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-compliant hostnames, including /, ?, #, and @. Because req.host returns the full parsed value, applications that validate hosts using naive prefix or suffix checks can be bypassed. This can lead to host header poisoning in applications that use req.host, req.url, or req.base_url for link generation, redirects, or origin validation. This issue has been patched in versions 3.1.21 and 3.2.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g2pf-xv49-m2h5</id>
    <title>GHSA-g2pf-xv49-m2h5 — Rack::Request accepts invalid Host characters, enabling host allowlist bypass</title>
    <updated>2026-10-02T23:31:32.100742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: rack</p>
<p>## Summary</p>
<p>`Rack::Request` parses the `Host` header using an `AUTHORITY` regular expression that accepts characters not permitted in RFC-compliant hostnames, including `/`, `?`, `#`, and `@`. Because `req.host` returns the full parsed value, applications that validate hosts using naive prefix or suffix checks can be bypassed.</p>
<p>For example, a check such as `req.host.start_with?("myapp.com")` can be bypassed with `Host: myapp.com@evil.com`, and a check such as `req.host.end_with?("myapp.com")` can be bypassed with `Host: evil.com/myapp.com`.</p>
<p>This can lead to host header poisoning in applications that use `req.host`, `req.url`, or `req.base_url` for link generation, redirects, or origin validation.</p>
<p>## Details</p>
<p>`Rack::Request` parses the authority component using logic equivalent to:</p>
<p>```ruby
AUTHORITY = /
  \A
  (?&lt;host&gt;
    \[(?&lt;address&gt;#{ipv6})\]
    |
    (?&lt;address&gt;[[[:graph:]&amp;&amp;[^\[\]]]]*?)
  )
  (:(?&lt;port&gt;\d+))?
  \z
/x
```</p>
<p>The character class used for non-IPv6 hosts accepts nearly all printable characters except `[` and `]`. This includes reserved URI delimiters such as `@`, `/`, `?`, and `#`, which are not valid hostname characters under RFC 3986 host syntax.</p>
<p>As a result, values such as the following are accepted and returned through `req.host`:</p>
<p>```text
myapp.com@evil.com
evil.com/myapp.com
evil.com#myapp.com
```</p>
<p>Applications that attempt to allowlist hosts using string prefix or suffix checks may therefore treat attacker-controlled hosts as trusted. For example:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g2pf-xv49-m2h5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34835</id>
    <title>UBUNTU-CVE-2026-34835</title>
    <updated>2026-10-02T23:31:32.100804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: ruby-rack, Ubuntu:26.04:LTS: ruby-rack</p>
<p>Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-compliant hostnames, including /, ?, #, and @. Because req.host returns the full parsed value, applications that validate hosts using naive prefix or suffix checks can be bypassed. This can lead to host header poisoning in applications that use req.host, req.url, or req.base_url for link generation, redirects, or origin validation. This issue has been patched in versions 3.1.21 and 3.2.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34835"/>
  </entry>
</feed>
