<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T08:34:32.009779+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1051</id>
    <title>certfr-2025-avi-1051 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-06T08:34:32.061047+00:00</updated>
    <content>certfr-2025-avi-1051</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1051"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253330</id>
    <title>EUVD-2026-253330</title>
    <updated>2026-10-06T08:34:32.061093+00:00</updated>
    <content>EUVD-2026-253330</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59822</id>
    <title>fkie_cve-2025-59822</title>
    <updated>2026-10-06T08:34:32.061109+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers security controls, launch targeted attacks against active users, and poison web caches. A pre-requisite for exploitation involves the web application being deployed behind a reverse-proxy that forwards trailer headers. This issue has been patched in versions 1.0.0-M45 and 0.23.31.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-59822"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wcwh-7gfw-5wrr</id>
    <title>GHSA-wcwh-7gfw-5wrr — Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section</title>
    <updated>2026-10-06T08:34:32.061141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.http4s:http4s-ember-core_2.12, Maven: org.http4s:http4s-ember-core_2.13, Maven: org.http4s:http4s-ember-core_3</p>
<p>### Summary
http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section.
This vulnerability could enable attackers to:
- Bypass front-end servers security controls
- Launch targeted attacks against active users
- Poison web caches</p>
<p>Pre-requisites for the exploitation: the web appication has to be deployed behind a reverse-proxy that forwards trailer headers.</p>
<p>### Details
The HTTP chunked message parser, after parsing the last body chunk, calls `parseTrailers` (`ember-core/shared/src/main/scala/org/http4s/ember/core/ChunkedEncoding.scala#L122-142`).
This method parses the trailer section using `Parser.parse`, where the issue originates.</p>
<p>`parse` has a bug that allows to terminate the parsing before finding the double CRLF condition: when it finds an header line that **does not include the colon character**, it continues parsing with `state=false` looking for the header name till reaching the condition `else if (current == lf &amp;&amp; (idx &gt; 0 &amp;&amp; message(idx - 1) == cr))` that sets `complete=true` even if no `\r\n\r\n` is  found.
```scala
if (current == colon) {
  state = true // set state to check for header value
  name = new String(message, start, idx - start) // extract name string
  start = idx + 1 // advance past colon for next start</p>
<p>// TODO: This if clause may not be necessary since the header value parser trims
  if (message.size &gt; idx + 1 &amp;&amp; message(idx + 1) == space) {
    start += 1 // if colon is followed by space advance again…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wcwh-7gfw-5wrr"/>
  </entry>
</feed>
