<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:24:25.655950+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ed19767</id>
    <title>Withdrawn: CLEANSTART-2026-ED19767 — Security fixes in opensearch-dashboards-fips 3.6.0-r4</title>
    <updated>2026-10-03T14:24:25.708564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: opensearch-dashboards-fips</p>
<p>Package opensearch-dashboards-fips version 3.6.0-r4 fixes 7 vulnerabilities: ghsa-cmwh-pvxp-8882, CVE-2026-12143, CVE-2026-46625, CVE-2026-53550, CVE-2026-53655...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ed19767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338888</id>
    <title>EUVD-2026-338888</title>
    <updated>2026-10-03T14:24:25.708621+00:00</updated>
    <content>EUVD-2026-338888</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338888"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44979</id>
    <title>fkie_cve-2026-44979</title>
    <updated>2026-10-03T14:24:25.708638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers are stripped, and the standard credential header Proxy-Authorization is forwarded intact to the redirect target, potentially exposing forward-proxy credentials to a host outside the original trust boundary when redirects are enabled through the redirects option or Wreck.defaults({ redirects: ... }). This issue is fixed in version 18.1.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vhjm-w67q-g75c</id>
    <title>GHSA-vhjm-w67q-g75c — @hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects</title>
    <updated>2026-10-03T14:24:25.708663+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @hapi/wreck</p>
<p>### Impact
When `@hapi/wreck` follows a 3xx redirect to a different hostname, only the `Authorization` and `Cookie` headers are stripped. The standard credential header `Proxy-Authorization` is forwarded intact to the redirect target, potentially exposing forward-proxy credentials to a host outside the original trust boundary.</p>
<p>Redirect following is opt-in. The redirects option defaults to false (no redirections followed), so applications are only affected if they have explicitly set redirects to a positive integer on the request or via `Wreck.defaults({ redirects: ... })`.</p>
<p>### Patches
`@hapi/wreck` 18.1.1 extends the cross-hostname strip set to include `proxy-authorization`. Upgrade to 18.1.1 or later.</p>
<p>### Workarounds
If upgrading is not immediately possible:
- Leave redirects at its default (`false`) — applications that never enable redirect following are not affected.
- If redirects are required, set redirects: 0 when calling endpoints with sensitive headers, or strip Proxy-Authorization from the headers before issuing the request.
- Use the `beforeRedirect` hook to manually strip proxy-authorization (and any other sensitive application headers) when `redirectOptions` targets a different hostname than the original request.</p>
<p>### Resources
- Related: [CVE-2024-30260 / GHSA-3787-6prv-h9w3 ](https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3)(undici)
- [RFC 7235 §4.4 — Proxy-Authorization](https://datatracker.ietf.org/doc/html/rfc7235#section-4.4)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vhjm-w67q-g75c"/>
  </entry>
</feed>
