<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:12:36 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00333</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00333</link>
      <description>bdu:2022-00333</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00333</guid>
    </item>
    <item>
      <title>certfr-2022-avi-113 — De multiples vulnérabilités ont été découvertes dans les produits
NetApp. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-113</link>
      <description>certfr-2022-avi-113</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-113</guid>
    </item>
    <item>
      <title>EUVD-2026-246278</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-246278</link>
      <description>EUVD-2026-246278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-246278</guid>
    </item>
    <item>
      <title>fkie_cve-2019-20444</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-20444</link>
      <description>&lt;p&gt;HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;#34;invalid fold.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;#34;invalid fold.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-20444</guid>
    </item>
    <item>
      <title>GHSA-cqqj-4p63-rrmm — HTTP Request Smuggling in Netty</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cqqj-4p63-rrmm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http, Maven: org.jboss.netty:netty, Maven: io.netty:netty&lt;/p&gt;
&lt;p&gt;HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;#34;invalid fold.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http, Maven: org.jboss.netty:netty, Maven: io.netty:netty&lt;/p&gt;
&lt;p&gt;HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;#34;invalid fold.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cqqj-4p63-rrmm</guid>
    </item>
    <item>
      <title>gsd-2019-20444</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-20444</link>
      <description>gsd-2019-20444</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-20444</guid>
    </item>
    <item>
      <title>OESA-2024-2066 — netty3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2066</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: netty3&lt;/p&gt;
&lt;p&gt;Netty is a NIO client server framework which enables quick and easy development of network applications such as protocol servers and clients. It greatly simplifies and streamlines network programming such as TCP and UDP socket server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;amp;quot;Transfer-Encoding : chunked&amp;amp;quot; line), which leads to HTTP request smuggling.(CVE-2019-16869)&#13;
&#13;
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;amp;quot;invalid fold.&amp;amp;quot;(CVE-2019-20444)&#13;
&#13;
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.(CVE-2019-20445)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: netty3&lt;/p&gt;
&lt;p&gt;Netty is a NIO client server framework which enables quick and easy development of network applications such as protocol servers and clients. It greatly simplifies and streamlines network programming such as TCP and UDP socket server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a &amp;amp;quot;Transfer-Encoding : chunked&amp;amp;quot; line), which leads to HTTP request smuggling.(CVE-2019-16869)&#13;
&#13;
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;amp;quot;invalid fold.&amp;amp;quot;(CVE-2019-20444)&#13;
&#13;
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.(CVE-2019-20445)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2066</guid>
    </item>
    <item>
      <title>RHSA-2020:0497 — Red Hat Security Advisory: AMQ Online security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:0497</link>
      <description>&lt;p&gt;netty: HTTP request smuggling netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty: HTTP request smuggling netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:0497</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-20444</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-20444</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:16.04:LTS: netty-3.9, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:18.04:LTS: netty, Ubuntu:18.04:LTS: netty-3.9&lt;/p&gt;
&lt;p&gt;HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;#34;invalid fold.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:16.04:LTS: netty-3.9, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:18.04:LTS: netty, Ubuntu:18.04:LTS: netty-3.9&lt;/p&gt;
&lt;p&gt;HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an &amp;#34;invalid fold.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-20444</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2133 — JFrog Artifactory: Mehrere Schwachstellen in Drittanbieter-Komponenten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2133</link>
      <description>&lt;p&gt;JFrog Artifactory nutzt verschiedene Komponenten von Drittanbietern. Diese enthalten mehrere Schwachstellen. Neuen Informationen von JFrog zufolge sind diese Schwachstellen jedoch nicht in Produkten von JFrog ausnutzbar.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;JFrog Artifactory nutzt verschiedene Komponenten von Drittanbietern. Diese enthalten mehrere Schwachstellen. Neuen Informationen von JFrog zufolge sind diese Schwachstellen jedoch nicht in Produkten von JFrog ausnutzbar.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2133</guid>
    </item>
  </channel>
</rss>
