<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T17:19:44.856047+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:36187</id>
    <title>ALSA-2026:36187 — Important: perl-HTTP-Daemon security update</title>
    <updated>2026-10-07T17:19:44.875981+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: perl-HTTP-Daemon</p>
<p>The perl-HTTP-Daemon package includes the [HTTP::Daemon](HTTP::Daemon) class, a subclass of IO::Socket::IP. Instances of the [HTTP::Daemon](HTTP::Daemon) class are HTTP/1.1 servers that listen on a socket for incoming requests.</p>
<p>Security Fix(es):</p>
<p>* perl-HTTP-Daemon: [HTTP::Daemon:](HTTP::Daemon:) Arbitrary code execution via OS command injection in send_file() (CVE-2026-8450)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:36187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-texlive-cve-2026-8450</id>
    <title>BREW-texlive-CVE-2026-8450 — HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()</title>
    <updated>2026-10-07T17:19:44.876072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: texlive</p>
<p>HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().</p>
<p>send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '&gt; path' and '&gt;&gt; path' open the path for write or append.</p>
<p>Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-texlive-cve-2026-8450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337149</id>
    <title>EUVD-2026-337149</title>
    <updated>2026-10-07T17:19:44.876141+00:00</updated>
    <content>EUVD-2026-337149</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8450</id>
    <title>fkie_cve-2026-8450</title>
    <updated>2026-10-07T17:19:44.876171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().</p>
<p>send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '&gt; path' and '&gt;&gt; path' open the path for write or append.</p>
<p>Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-8450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3hc6-3p33-wq57</id>
    <title>GHSA-3hc6-3p33-wq57</title>
    <updated>2026-10-07T17:19:44.876230+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().</p>
<p>send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '&gt; path' and '&gt;&gt; path' open the path for write or append.</p>
<p>Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3hc6-3p33-wq57"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-8450</id>
    <title>msrc_CVE-2026-8450 — HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()</title>
    <updated>2026-10-07T17:19:44.876272+00:00</updated>
    <content>msrc_CVE-2026-8450</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-8450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10938-1</id>
    <title>openSUSE-SU-2026:10938-1 — perl-HTTP-Daemon-6.170.0-1.1 on GA media</title>
    <updated>2026-10-07T17:19:44.876311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl-HTTP-Daemon-6.170.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10938-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:36187</id>
    <title>RLSA-2026:36187 — Important: perl-HTTP-Daemon security update</title>
    <updated>2026-10-07T17:19:44.876345+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: perl-HTTP-Daemon</p>
<p>The perl-HTTP-Daemon package includes the HTTP::Daemon class, a subclass of IO::Socket::IP. Instances of the HTTP::Daemon class are HTTP/1.1 servers that listen on a socket for incoming requests.</p>
<p>Security Fix(es):</p>
<p>* perl-HTTP-Daemon: HTTP::Daemon: Arbitrary code execution via OS command injection in send_file() (CVE-2026-8450)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:36187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22187-1</id>
    <title>SUSE-SU-2026:22187-1 — Security update for perl-HTTP-Daemon</title>
    <updated>2026-10-07T17:19:44.876403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for perl-HTTP-Daemon</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22187-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8450</id>
    <title>UBUNTU-CVE-2026-8450</title>
    <updated>2026-10-07T17:19:44.876440+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libhttp-daemon-perl, Ubuntu:Pro:16.04:LTS: libhttp-daemon-perl, Ubuntu:Pro:18.04:LTS: libhttp-daemon-perl, Ubuntu:Pro:20.04:LTS: libhttp-daemon-perl, Ubuntu:22.04:LTS: libhttp-daemon-perl, Ubuntu:24.04:LTS: libhttp-daemon-perl, Ubuntu:25.10: libhttp-daemon-perl, Ubuntu:26.04:LTS: libhttp-daemon-perl</p>
<p>HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '&gt; path' and '&gt;&gt; path' open the path for write or append. Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pipe form ('cmd |') also leaks subprocess stdout into the HTTP response body. The write-mode forms can create or truncate files at attacker chosen paths.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2218</id>
    <title>WID-SEC-W-2026-2218 — Red Hat Enterprise Linux (perl-HTTP-Daemon): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rec…</title>
    <updated>2026-10-07T17:19:44.876515+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2218"/>
  </entry>
</feed>
