<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T21:55:49.299374+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369545</id>
    <title>EUVD-2026-369545</title>
    <updated>2026-10-05T21:55:49.346410+00:00</updated>
    <content>EUVD-2026-369545</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84997</id>
    <title>fkie_cve-2026-84997</title>
    <updated>2026-10-05T21:55:49.346452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete terminal-chunk trailer without CRLF left the buffer unchanged after strpos returned false, and exactly two non-CRLF bytes after a completed non-terminal chunk bypassed both the error and wait guards. The affected decoder processes request bodies for React\Http\HttpServer and response bodies for React\Http\Browser, allowing a malicious client to freeze a server or a malicious or compromised server to freeze a client. A reverse proxy that normalizes inbound requests may protect the server direction but does not protect outbound Browser requests. This issue is fixed in version 1.11.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-84997"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x424-64qh-5j54</id>
    <title>GHSA-x424-64qh-5j54 — react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU</title>
    <updated>2026-10-05T21:55:49.346490+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: react/http</p>
<p>### Summary</p>
<p>A malformed HTTP message using `Transfer-Encoding: chunked` can drive `React\Http\Io\ChunkedDecoder` into an infinite loop, pegging a CPU core and freezing the event loop. Because ReactPHP is single-threaded, one such message stalls the entire process for every client until it is killed.</p>
<p>Both directions are affected. `ChunkedDecoder` decodes chunked **request** bodies for `React\Http\HttpServer` and chunked **response** bodies for `React\Http\Browser`, so a server can be attacked by a malicious client and a client can be attacked by a malicious or compromised server.</p>
<p>### Details</p>
<p>`ChunkedDecoder::handleData()` loops `while ($this-&gt;buffer !== '')` and relies on the buffer shrinking each iteration. Two states leave the buffer unchanged while the loop condition stays true.</p>
<p>**Terminal-chunk trailer.** After the terminating `0` chunk, any remaining buffer is treated as trailer data to skip:</p>
<p>```php
} elseif ($this-&gt;chunkSize === 0) {
    $this-&gt;buffer = (string)\substr($this-&gt;buffer, $positionCrlf);
}
```</p>
<p>When the trailer holds no CRLF yet, `strpos()` returns `false`, PHP coerces that to `0` in `substr()`, and the buffer is never advanced. Neither the error guard (which requires a non-zero chunk size) nor the wait guard (which requires fewer than two bytes remaining) can fire, so the loop re-enters with identical state.</p>
<p>**Off-by-one after a completed chunk.** Once a non-terminal chunk has been fully transferred, the "chunk does not end with a CRLF" error guard r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x424-64qh-5j54"/>
  </entry>
</feed>
