<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T10:07:44.616987+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322090</id>
    <title>EUVD-2026-322090</title>
    <updated>2026-10-06T10:07:44.714670+00:00</updated>
    <content>EUVD-2026-322090</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47069</id>
    <title>fkie_cve-2026-47069</title>
    <updated>2026-10-06T10:07:44.714728+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Splitting. The hackney_cookie:setcookie/3 function in src/hackney_cookie.erl validates the Name and Value arguments against CRLF and control characters, but concatenates the domain and path options verbatim into the output iolist with no equivalent check. An attacker who controls either option — for example by supplying a Host header value forwarded as the cookie domain, or a request path forwarded as the cookie path — can inject a literal CRLF sequence and arbitrary additional Set-Cookie headers into the HTTP response.</p>
<p>This issue affects hackney: from 0.9.0 before 4.0.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mp55-p8c9-rfw2</id>
    <title>GHSA-mp55-p8c9-rfw2 — Hackney has CRLF / header injection via unvalidated `domain` and `path` options</title>
    <updated>2026-10-06T10:07:44.714791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Hex: hackney</p>
<p>### Summary</p>
<p>CRLF injection in `hackney_cookie:setcookie/3` (`src/hackney_cookie.erl`). The function validates `Name` and `Value` against CR/LF and control characters but concatenates the `domain` and `path` options verbatim into the output binary. If either option carries attacker-controlled data, a `Host` header forwarded as the cookie domain, a request URI forwarded as the cookie path, a `\r\n` in the value splits the `Set-Cookie` header and lets the attacker inject additional headers into the HTTP response.</p>
<p>### Details</p>
<p>**1. Asymmetric validation**</p>
<p>Lines 27–34 of `hackney_cookie.erl` run `binary:match` on `Name` and `Value`, rejecting `=`, `,`, `;`, whitespace, `\r`, `\n`, `\013`, and `\014`. The `Domain` and `Path` options (lines 47 and 51) skip this check entirely and land straight in the result iolist:</p>
<p>```erlang
[&lt;&lt;"; Domain="&gt;&gt;, Domain]
[&lt;&lt;"; Path="&gt;&gt;,   Path]
```</p>
<p>`iolist_to_binary(...)` on line 63 flattens everything and returns it to the caller.</p>
<p>**2. Injection**</p>
<p>A `Path` of `&lt;&lt;"/x\r\nSet-Cookie: admin=1; Path=/"&gt;&gt;` produces a binary with a literal `\r\n`. Written into a `Set-Cookie` response header, the receiving HTTP parser splits it into two headers — one legitimate, one attacker-controlled.</p>
<p>**3. Realistic trigger**</p>
<p>Common patterns: keying the cookie domain off `Host`, deriving the path from the request URI, or copying a `Location` path into a cookie. Any of these lets a remote attacker control the injected content.</p>
<p>### PoC</p>
<p>1. Call `hackney_cookie:setco…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mp55-p8c9-rfw2"/>
  </entry>
</feed>
