<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:35:13.207249+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06476</id>
    <title>bdu:2026-06476</title>
    <updated>2026-10-03T09:35:13.326164+00:00</updated>
    <content>bdu:2026-06476</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0490</id>
    <title>certfr-2026-avi-0490 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer une atteinte…</title>
    <updated>2026-10-03T09:35:13.326212+00:00</updated>
    <content>certfr-2026-avi-0490</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-fp02256</id>
    <title>CLEANSTART-2026-FP02256 — Security fix for CVE-2026-40912 applied in: forecastle 1.0.159-r1</title>
    <updated>2026-10-03T09:35:13.326249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: forecastle</p>
<p>Security vulnerability affects the forecastle package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-fp02256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337266</id>
    <title>EUVD-2026-337266</title>
    <updated>2026-10-03T09:35:13.326296+00:00</updated>
    <content>EUVD-2026-337266</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337266"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40912</id>
    <title>fkie_cve-2026-40912</title>
    <updated>2026-10-03T09:35:13.326325+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middleware when used in combination with ForwardAuth, BasicAuth, or DigestAuth. The middleware matches the regex against the decoded URL path but uses the resulting byte length to slice the percent-encoded raw path. When a dot (or multiple dots) appears in the prefix portion of the URL, the raw path after stripping becomes a dot-segment (e.g. /./admin/secret). ForwardAuth receives this dot-segment path in X-Forwarded-Uri, which does not match the protected path patterns and therefore allows the request through. The backend then normalizes the dot-segment to the real path per RFC 3986 and serves the protected content An unauthenticated attacker can exploit this against any backend that performs dot-segment normalization. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6jwx-7vp4-9847</id>
    <title>GHSA-6jwx-7vp4-9847 — Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync</title>
    <updated>2026-10-03T09:35:13.326360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/traefik/traefik/v3, Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik</p>
<p>## Summary</p>
<p>There is a high severity authentication bypass vulnerability in Traefik's `StripPrefixRegex` middleware when used in combination with `ForwardAuth`, `BasicAuth`, or `DigestAuth`.</p>
<p>The middleware matches the regex against the decoded URL path but uses the resulting byte length to slice the percent-encoded raw path. When a dot (or multiple dots) appears in the prefix portion of the URL, the raw path after stripping becomes a dot-segment (e.g. `/./admin/secret`).</p>
<p>`ForwardAuth` receives this dot-segment path in `X-Forwarded-Uri`, which does not match the protected path patterns and therefore allows the request through. The backend then normalizes the dot-segment to the real path per RFC 3986 and serves the protected content</p>
<p>An unauthenticated attacker can exploit this against any backend that performs dot-segment normalization.</p>
<p>## Patches</p>
<p>- https://github.com/traefik/traefik/releases/tag/v2.11.43
- https://github.com/traefik/traefik/releases/tag/v3.6.14
- https://github.com/traefik/traefik/releases/tag/v3.7.0-rc.2</p>
<p>## For more information</p>
<p>If there are any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).</p>
<p>&lt;details&gt;
&lt;summary&gt;Original Description&lt;/summary&gt;</p>
<p>### Summary</p>
<p>StripPrefixRegex uses the byte length of a decoded Path match to slice the encoded RawPath. When percent-encoded characters are in the prefix region, this produces a wrong RawPath. ForwardAuth then
  receives this wrong path in X-Forwar…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6jwx-7vp4-9847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10697-1</id>
    <title>openSUSE-SU-2026:10697-1 — traefik-3.6.15-1.1 on GA media</title>
    <updated>2026-10-03T09:35:13.326450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>traefik-3.6.15-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10697-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:21772</id>
    <title>RHSA-2026:21772 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.28.0 Release.</title>
    <updated>2026-10-03T09:35:13.326484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter markdown-it: markdown-it: Denial of Service via Regular Expression Denial of Service in linkify function bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions svgo: SVGO: Denial of Service via XML entity expansion express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking tar: tar: File overwrite via drive-relative symlink traversal flatted: flatted: Unbounded recursion DoS in parse() revive phase crypto/x509: crypto/tls: golang: Go: Denial of Service vulnera…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:21772"/>
  </entry>
</feed>
