<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:12:59 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00270</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00270</link>
      <description>bdu:2022-00270</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00270</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2019-17567 — CVE-2019-17567 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2019-17567</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2019-17567</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0575 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575</link>
      <description>certfr-2024-avi-0575</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575</guid>
    </item>
    <item>
      <title>cnvd-2021-44766</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-44766</link>
      <description>cnvd-2021-44766</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-44766</guid>
    </item>
    <item>
      <title>EUVD-2026-58415</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-58415</link>
      <description>EUVD-2026-58415</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-58415</guid>
    </item>
    <item>
      <title>fkie_cve-2019-17567</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-17567</link>
      <description>&lt;p&gt;Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-17567</guid>
    </item>
    <item>
      <title>GHSA-qf63-wqjv-7x2f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qf63-wqjv-7x2f</link>
      <description>&lt;p&gt;Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qf63-wqjv-7x2f</guid>
    </item>
    <item>
      <title>gsd-2019-17567</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-17567</link>
      <description>gsd-2019-17567</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-17567</guid>
    </item>
    <item>
      <title>msrc_CVE-2019-17567 — mod_proxy_wstunnel tunneling of non Upgraded connections</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2019-17567</link>
      <description>msrc_CVE-2019-17567</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2019-17567</guid>
    </item>
    <item>
      <title>OESA-2023-1222 — httpd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1222</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP3: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.(CVE-2019-17567)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP3: httpd&lt;/p&gt;
&lt;p&gt;Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.(CVE-2019-17567)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1222</guid>
    </item>
    <item>
      <title>RHSA-2021:4613 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP10 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:4613</link>
      <description>&lt;p&gt;httpd: mod_proxy_wstunnel tunneling of non Upgraded connection pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1 httpd: mod_proxy NULL pointer dereference pcre: Integer overflow when parsing callout numeric arguments httpd: Single zero byte stack overflow in mod_auth_digest JBCS: URL normalization issue with dot-dot-semicolon(s) leads to information disclosure openssl: Read buffer overruns processing ASN.1 strings openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash() httpd: mod_session: NULL pointer dereference when parsing Cookie header httpd: mod_session: Heap overflow via a crafted SessionHeader value httpd: Unexpected URL matching with &amp;#39;MergeSlashes OFF&amp;#39; httpd: NULL pointer dereference via malformed requests&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;httpd: mod_proxy_wstunnel tunneling of non Upgraded connection pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1 httpd: mod_proxy NULL pointer dereference pcre: Integer overflow when parsing callout numeric arguments httpd: Single zero byte stack overflow in mod_auth_digest JBCS: URL normalization issue with dot-dot-semicolon(s) leads to information disclosure openssl: Read buffer overruns processing ASN.1 strings openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash() httpd: mod_session: NULL pointer dereference when parsing Cookie header httpd: mod_session: Heap overflow via a crafted SessionHeader value httpd: Unexpected URL matching with &amp;#39;MergeSlashes OFF&amp;#39; httpd: NULL pointer dereference via malformed requests&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:4613</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-17567</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-17567</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: apache2, Ubuntu:Pro:16.04:LTS: apache2, Ubuntu:Pro:18.04:LTS: apache2, Ubuntu:Pro:20.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-17567</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0438 — Apache HTTP Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0438</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder sonstige Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder sonstige Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0438</guid>
    </item>
  </channel>
</rss>
