<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:43:05.469632+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326664</id>
    <title>EUVD-2026-326664</title>
    <updated>2026-10-03T20:43:05.535950+00:00</updated>
    <content>EUVD-2026-326664</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48998</id>
    <title>fkie_cve-2026-48998</title>
    <updated>2026-10-03T20:43:05.535990+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. An attacker can provide a malformed Host header containing URI authority delimiters, such as `trusted.example@evil.example`. When the Host value is used to construct a URI, the malformed value can be reinterpreted as URI userinfo and host. This can cause the PSR-7 request URI host to differ from the original Host header value. Applications are affected if they parse attacker-controlled raw HTTP requests with `GuzzleHttp\Psr7\Message::parseRequest()` or the legacy 1.x `GuzzleHttp\Psr7\parse_request()` function, or if they build server requests from attacker-controlled server variables, then rely on the resulting URI host for routing, allow-list checks, or forwarding decisions. In affected forwarding or gateway scenarios, this may cause requests or credentials to be sent to an unintended host. The issue is patched in `2.10.2`. `1.x` is end-of-life and will not receive a patch. Some workarounds are available. Validate the `Host` header as `uri-host [ ":" port ]` before calling `Message::parseRequest()` or legacy `parse_request()` on untrusted HTTP request data, or before deriving routing and forwarding decisions from a parsed request URI. Reject Host values containing userinfo, path, query, or fragment delimiters.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48998"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-34xg-wgjx-8xph</id>
    <title>GHSA-34xg-wgjx-8xph — guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation</title>
    <updated>2026-10-03T20:43:05.536036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: guzzlehttp/psr7</p>
<p>## Impact</p>
<p>`guzzlehttp/psr7` improperly interpreted malformed `Host` header values when constructing request URIs from inbound request data. This issue concerns inbound request parsing and server request construction. It does not require serializing a PSR-7 request, and it is not part of the normal outbound request-sending path used by `guzzlehttp/guzzle`.</p>
<p>A vulnerable flow is:</p>
<p>1. An attacker controls a raw HTTP request or server variable containing a `Host` value.
2. The `Host` value contains URI authority delimiters, such as `trusted.example@evil.example`.
3. `guzzlehttp/psr7` uses that value to construct a URI.
4. The URI parser treats the portion before `@` as userinfo and the portion after `@` as the URI host.
5. The resulting PSR-7 request URI host differs from the original `Host` header value.</p>
<p>For example, `Host: trusted.example@evil.example` can result in a PSR-7 URI whose host is `evil.example`, while the original Host header value remains `trusted.example@evil.example`.</p>
<p>Applications are affected if they parse attacker-controlled raw HTTP requests with `GuzzleHttp\Psr7\Message::parseRequest()` or the legacy 1.x `GuzzleHttp\Psr7\parse_request()` function, or if they build server requests from attacker-controlled server variables with `GuzzleHttp\Psr7\ServerRequest::fromGlobals()` or `GuzzleHttp\Psr7\ServerRequest::getUriFromGlobals()`, and then rely on the resulting URI host for routing, allow-list checks, credential selection, or forwarding decisions. Applicatio…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-34xg-wgjx-8xph"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0375</id>
    <title>NCSC-2026-0375 — Kwetsbaarheden verholpen in Oracle Communications</title>
    <updated>2026-10-03T20:43:05.536084+00:00</updated>
    <content>NCSC-2026-0375</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0375"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48998</id>
    <title>UBUNTU-CVE-2026-48998</title>
    <updated>2026-10-03T20:43:05.536148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: php-guzzlehttp-psr7, Ubuntu:20.04:LTS: php-guzzlehttp-psr7, Ubuntu:Pro:22.04:LTS: php-guzzlehttp-psr7, Ubuntu:24.04:LTS: php-guzzlehttp-psr7, Ubuntu:25.10: php-guzzlehttp-psr7, Ubuntu:26.04:LTS: php-guzzlehttp-psr7</p>
<p>guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. An attacker can provide a malformed Host header containing URI authority delimiters, such as `trusted.example@evil.example`. When the Host value is used to construct a URI, the malformed value can be reinterpreted as URI userinfo and host. This can cause the PSR-7 request URI host to differ from the original Host header value. Applications are affected if they parse attacker-controlled raw HTTP requests with `GuzzleHttp\Psr7\Message::parseRequest()` or the legacy 1.x `GuzzleHttp\Psr7\parse_request()` function, or if they build server requests from attacker-controlled server variables, then rely on the resulting URI host for routing, allow-list checks, or forwarding decisions. In affected forwarding or gateway scenarios, this may cause requests or credentials to be sent to an unintended host. The issue is patched in `2.10.2`. `1.x` is end-of-life and will not receive a patch. Some workarounds are available. Validate the `Host` header as `uri-host [ ":" port ]` before calling `Message::parseRequest()` or legacy `parse_request()` on untrusted HTTP request data, or before deriving routing and forwarding decisions from a parsed request URI. Reject Host values containing userinfo, path, query, or fragment delimiters.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48998"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3403</id>
    <title>WID-SEC-W-2026-3403 — Oracle Communications: Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:43:05.536187+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3403"/>
  </entry>
</feed>
