<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T23:16:39.709683+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00065</id>
    <title>bdu:2026-00065</title>
    <updated>2026-10-06T23:16:39.785209+00:00</updated>
    <content>bdu:2026-00065</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00065"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248757</id>
    <title>EUVD-2026-248757</title>
    <updated>2026-10-06T23:16:39.785247+00:00</updated>
    <content>EUVD-2026-248757</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248757"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54581</id>
    <title>fkie_cve-2025-54581</title>
    <updated>2026-10-06T23:16:39.785262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vproxy is an HTTP/HTTPS/SOCKS5 proxy server. In versions 2.3.3 and below, untrusted data is extracted from the user-controlled HTTP Proxy-Authorization header and passed to Extension::try_from and flows into parse_ttl_extension where it is parsed as a TTL value. If an attacker supplies a TTL of zero (e.g. by using a username such as 'configuredUser-ttl-0'), the modulo operation 'timestamp % ttl' will cause a division by zero panic, causing the server to crash causing a denial-of-service. This is fixed in version 2.4.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-54581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7h24-c332-p48c</id>
    <title>GHSA-7h24-c332-p48c — vproxy Divide by Zero DoS Vulnerability</title>
    <updated>2026-10-06T23:16:39.785296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: vproxy</p>
<p>### Summary
Untrusted, user-controlled data from the HTTP Proxy-Authorization header can induce a denial of service state.</p>
<p>### Details
Untrusted data is extracted from the user-controlled HTTP Proxy-Authorization header and passed to Extension::try_from and flows into parse_ttl_extension where it is parsed as a TTL value. If an attacker supplies a TTL of zero (e.g. by using a username such as 'configuredUser-ttl-0'), the modulo operation 'timestamp % ttl' will cause a division by zero panic, causing the server to crash causing a denial-of-service.</p>
<p>The code assumed to be responsible for this can be found here: https://github.com/0x676e67/vproxy/blob/ab304c3854bf8480be577039ada0228907ba0923/src/extension.rs#L173-L183</p>
<p>### PoC
1. Download and run the latest version of vproxy
2. Send a cUrl request like the following, adjusting address and port as necessary: ```curl -x "http://test-ttl-0:test@127.0.0.1:8101" https://google.com```
3. Wait for a cUrl error indicating "Proxy CONNECT aborted"
4. View logs from the vproxy server
5. Observe that the vproxy server crashed due to a divide-by-zero panic</p>
<p>### Impact
The resulting crash renders the proxy server unusable until it is reset.</p>
<p>Finally, one last note: I'm reporting this on behalf of another researcher at Black Duck. Credit for discovery should be attributed to David Bohannon ([dbohannon](https://github.com/dbohannon))</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7h24-c332-p48c"/>
  </entry>
</feed>
