<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T21:52:27.984746+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-05797</id>
    <title>bdu:2024-05797</title>
    <updated>2026-10-10T21:52:27.991931+00:00</updated>
    <content>bdu:2024-05797</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-05797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-35169</id>
    <title>cnvd-2024-35169</title>
    <updated>2026-10-10T21:52:27.991963+00:00</updated>
    <content>cnvd-2024-35169</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-35169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258452</id>
    <title>EUVD-2026-258452</title>
    <updated>2026-10-10T21:52:27.991977+00:00</updated>
    <content>EUVD-2026-258452</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258452"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-38522</id>
    <title>fkie_cve-2023-38522</title>
    <updated>2026-10-10T21:52:27.991989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.</p>
<p>This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.</p>
<p>Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-38522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-68qf-xhq3-9qj5</id>
    <title>GHSA-68qf-xhq3-9qj5</title>
    <updated>2026-10-10T21:52:27.992059+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.</p>
<p>This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.</p>
<p>Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-68qf-xhq3-9qj5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-38522</id>
    <title>gsd-2023-38522</title>
    <updated>2026-10-10T21:52:27.992077+00:00</updated>
    <content>gsd-2023-38522</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-38522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1955</id>
    <title>OESA-2024-1955 — trafficserver security update</title>
    <updated>2026-10-10T21:52:27.992088+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: trafficserver</p>
<p>Apache Traffic Server is an OpenSource HTTP / HTTPS / HTTP/2 / QUIC reverse, forward and transparent proxy and cache.

Security Fix(es):

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.

Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.(CVE-2023-38522)

Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.

Users can set a new setting (proxy.config.http.drop_chunked_trailers) not to forward chunked trailer section.
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.(CVE-2024-35161)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1955"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38522</id>
    <title>UBUNTU-CVE-2023-38522</title>
    <updated>2026-10-10T21:52:27.992115+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: trafficserver, Ubuntu:18.04:LTS: trafficserver, Ubuntu:Pro:20.04:LTS: trafficserver, Ubuntu:Pro:22.04:LTS: trafficserver, Ubuntu:24.04:LTS: trafficserver</p>
<p>Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1713</id>
    <title>WID-SEC-W-2024-1713 — Apache Traffic Server: Mehrere Schwachstellen</title>
    <updated>2026-10-10T21:52:27.992141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache Traffic Server ausnutzen, um einen Denial of Service Angriff durchzuführen oder Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1713"/>
  </entry>
</feed>
