<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:02:25.795323+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276722</id>
    <title>EUVD-2026-276722</title>
    <updated>2026-10-06T16:02:25.848585+00:00</updated>
    <content>EUVD-2026-276722</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276722"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32873</id>
    <title>fkie_cve-2026-32873</title>
    <updated>2026-10-06T16:02:25.848637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ewe is a Gleam web server. Versions 0.8.0 through 3.0.4 contain a bug in the handle_trailers function where rejected trailer headers (forbidden or undeclared) cause an infinite loop. When handle_trailers encounters such a trailer, three code paths (lines 520, 523, 526) recurse with the original buffer (rest) instead of advancing past the rejected header (Buffer(header_rest, 0)), causing decoder.decode_packet to re-parse the same header on every iteration. The resulting loop has no timeout or escape — the BEAM process permanently wedges at 100% CPU. Any application that calls ewe.read_body on chunked requests is affected, and this is exploitable by any unauthenticated remote client before control returns to application code, making an application-level workaround impossible. This issue is fixed in version 3.0.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32873"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4w98-xf39-23gp</id>
    <title>GHSA-4w98-xf39-23gp — Loop with Unreachable Exit Condition ('Infinite Loop') in ewe</title>
    <updated>2026-10-06T16:02:25.848723+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Hex: ewe</p>
<p>## Summary</p>
<p>ewe's `handle_trailers` function contains a bug where rejected trailer headers (forbidden or undeclared) cause an infinite loop. The function recurses with the original unparsed buffer instead of advancing past the rejected header, re-parsing the same header forever. Each malicious request permanently wedges a BEAM process at 100% CPU with no timeout or escape.</p>
<p>## Impact</p>
<p>When `handle_trailers` (`ewe/internal/http1.gleam:493`) encounters a trailer that is either not in the declared trailer set or is blocked by `is_forbidden_trailer`, three code paths (lines 520, 523, 526) recurse with the original buffer `rest` instead of `Buffer(header_rest, 0)`:</p>
<p>```gleam
// Line 523 — uses `rest` (original buffer), not `Buffer(header_rest, 0)` (remaining)
False -&gt; handle_trailers(req, set, rest)
```</p>
<p>This causes `decoder.decode_packet` to re-parse the same header on every iteration, producing an infinite loop. The BEAM process never yields, never times out, and never terminates.</p>
<p>**Any ewe application that calls `ewe.read_body` on chunked requests is affected.** This is exploitable by any unauthenticated remote client. There is no application-level workaround — the infinite loop is triggered inside `read_body` before control returns to application code.</p>
<p>### Proof of Concept</p>
<p>**Send a chunked request with a forbidden trailer (`host`) to trigger the infinite loop:**</p>
<p>```sh
printf 'POST / HTTP/1.1\r\nHost: localhost:8080\r\nTransfer-Encoding: chunked\r\nTrailer: host\r\n\r\n4\r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4w98-xf39-23gp"/>
  </entry>
</feed>
