<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:17:01.966506+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ag15773</id>
    <title>Withdrawn: CLEANSTART-2026-AG15773 — Security fixes in apache-hive 4.2.0-r4</title>
    <updated>2026-10-03T09:17:02.052568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-hive</p>
<p>Package apache-hive version 4.2.0-r4 fixes 2 vulnerabilities: CVE-2026-45205, CVE-2026-45300</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ag15773"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-325580</id>
    <title>EUVD-2026-325580</title>
    <updated>2026-10-03T09:17:02.052629+00:00</updated>
    <content>EUVD-2026-325580</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-325580"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45300</id>
    <title>fkie_cve-2026-45300</title>
    <updated>2026-10-03T09:17:02.052646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45300"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fmxf-pm6p-7xgm</id>
    <title>GHSA-fmxf-pm6p-7xgm — async-http-client: Cookie header not stripped on cross-origin redirect</title>
    <updated>2026-10-03T09:17:02.052673+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.asynchttpclient:async-http-client</p>
<p>## Summary</p>
<p>async-http-client leaks `Cookie` headers to cross-origin redirect targets. When following a redirect across a security boundary (different origin, or HTTPS→HTTP downgrade), the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip `Cookie`, so session cookies and other sensitive cookie values are forwarded to the redirect target — which may be attacker-controlled.</p>
<p>## Details</p>
<p>The vulnerability is in `client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java`.</p>
<p>The caller computes `stripAuth` on each redirect:</p>
<p>```java
boolean sameBase    = request.getUri().isSameBase(newUri);
boolean stripAuth   = !sameBase || schemeDowngrade || stripAuthorizationOnRedirect;
// ...
requestBuilder.setHeaders(propagatedHeaders(request, realm, keepBody, stripAuth));
```</p>
<p>`stripAuth` is `true` whenever the redirect crosses an origin, downgrades the scheme, or the caller opted in via `AsyncHttpClientConfig#isStripAuthorizationOnRedirect()`.</p>
<p>In the vulnerable version, `propagatedHeaders()` only removes `Authorization` and `Proxy-Authorization` in that branch — `Cookie` is left untouched:</p>
<p>```java
private static HttpHeaders propagatedHeaders(Request request, Realm realm, boolean keepBody, boolean stripAuthorization) {
    HttpHeaders headers = request.getHeaders()
            .remove(HOST)
            .remove(CONTENT_LENGTH);</p>
<p>if (!keepBody) {
        headers.remo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fmxf-pm6p-7xgm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45300</id>
    <title>UBUNTU-CVE-2026-45300</title>
    <updated>2026-10-03T09:17:02.052731+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: async-http-client, Ubuntu:16.04:LTS: async-http-client, Ubuntu:18.04:LTS: async-http-client, Ubuntu:Pro:20.04:LTS: async-http-client, Ubuntu:22.04:LTS: async-http-client, Ubuntu:24.04:LTS: async-http-client, Ubuntu:25.10: async-http-client, Ubuntu:26.04:LTS: async-http-client</p>
<p>The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45300"/>
  </entry>
</feed>
