<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:35:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-01935</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-01935</link>
      <description>bdu:2020-01935</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-01935</guid>
    </item>
    <item>
      <title>certfr-2022-avi-113 — De multiples vulnérabilités ont été découvertes dans les produits
NetApp. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-113</link>
      <description>certfr-2022-avi-113</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-113</guid>
    </item>
    <item>
      <title>EUVD-2026-246531</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-246531</link>
      <description>EUVD-2026-246531</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-246531</guid>
    </item>
    <item>
      <title>fkie_cve-2019-16869</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-16869</link>
      <description>&lt;p&gt;Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;#34;Transfer-Encoding : chunked&amp;#34; line), which leads to HTTP request smuggling.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;#34;Transfer-Encoding : chunked&amp;#34; line), which leads to HTTP request smuggling.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-16869</guid>
    </item>
    <item>
      <title>GHSA-p979-4mfw-53vg — HTTP Request Smuggling in Netty</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p979-4mfw-53vg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-all, Maven: org.jboss.netty:netty, Maven: io.netty:netty&lt;/p&gt;
&lt;p&gt;Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;#34;Transfer-Encoding : chunked&amp;#34; line), which leads to HTTP request smuggling.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-all, Maven: org.jboss.netty:netty, Maven: io.netty:netty&lt;/p&gt;
&lt;p&gt;Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;#34;Transfer-Encoding : chunked&amp;#34; line), which leads to HTTP request smuggling.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p979-4mfw-53vg</guid>
    </item>
    <item>
      <title>gsd-2019-16869</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-16869</link>
      <description>gsd-2019-16869</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-16869</guid>
    </item>
    <item>
      <title>OESA-2024-2066 — netty3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2066</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: netty3&lt;/p&gt;
&lt;p&gt;Netty is a NIO client server framework which enables quick and easy development of network applications such as protocol servers and clients. It greatly simplifies and streamlines network programming such as TCP and UDP socket server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;amp;quot;Transfer-Encoding : chunked&amp;amp;quot; line), which leads to HTTP request smuggling.(CVE-2019-16869)&#13;
&#13;
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;amp;quot;invalid fold.&amp;amp;quot;(CVE-2019-20444)&#13;
&#13;
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.(CVE-2019-20445)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: netty3&lt;/p&gt;
&lt;p&gt;Netty is a NIO client server framework which enables quick and easy development of network applications such as protocol servers and clients. It greatly simplifies and streamlines network programming such as TCP and UDP socket server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;amp;quot;Transfer-Encoding : chunked&amp;amp;quot; line), which leads to HTTP request smuggling.(CVE-2019-16869)&#13;
&#13;
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;amp;quot;invalid fold.&amp;amp;quot;(CVE-2019-20444)&#13;
&#13;
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.(CVE-2019-20445)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2066</guid>
    </item>
    <item>
      <title>RHSA-2019:3892 — Red Hat Security Advisory: Red Hat Fuse 7.5.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:3892</link>
      <description>&lt;p&gt;jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525) jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-15095) infinispan: deserialization of data in XML and JSON transcoders hadoop: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file tomcat: Host name verification missing in WebSocket client jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis activemq: ActiveMQ Client Missing TLS Hostname Verification tika: Incomplete fix allows for XML entity expansion resulting in denial of service jackson-databind: improper polymorphic deserialization of types from Jodd-db library jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver jackson-databind: arbitrary code execution in slf4j-ext class jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes jackson-databind: exfiltration/XXE in some JDK classes jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class jackson-databind: improper polymorphic deserialization in axis2-transport-jms class jackson-databind: improper polymorphic deserialization in openjpa class jackson-databind: improper polymorphic deserialization in jboss-common-core class retrofit: Directory traversal in RequestBuilder allows manipulation of resources zookeeper: Information disclosure in Apa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525) jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-15095) infinispan: deserialization of data in XML and JSON transcoders hadoop: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file tomcat: Host name verification missing in WebSocket client jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis activemq: ActiveMQ Client Missing TLS Hostname Verification tika: Incomplete fix allows for XML entity expansion resulting in denial of service jackson-databind: improper polymorphic deserialization of types from Jodd-db library jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver jackson-databind: arbitrary code execution in slf4j-ext class jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes jackson-databind: exfiltration/XXE in some JDK classes jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class jackson-databind: improper polymorphic deserialization in axis2-transport-jms class jackson-databind: improper polymorphic deserialization in openjpa class jackson-databind: improper polymorphic deserialization in jboss-common-core class retrofit: Directory traversal in RequestBuilder allows manipulation of resources zookeeper: Information disclosure in Apa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:3892</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-16869</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16869</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:16.04:LTS: netty-3.9, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:18.04:LTS: netty-3.9, Ubuntu:Pro:18.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;#34;Transfer-Encoding : chunked&amp;#34; line), which leads to HTTP request smuggling.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:16.04:LTS: netty-3.9, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:18.04:LTS: netty-3.9, Ubuntu:Pro:18.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;#34;Transfer-Encoding : chunked&amp;#34; line), which leads to HTTP request smuggling.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16869</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0770 — IBM DB2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</guid>
    </item>
  </channel>
</rss>
