<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:25:10 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-09009</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09009</link>
      <description>bdu:2025-09009</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09009</guid>
    </item>
    <item>
      <title>EUVD-2026-38088</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-38088</link>
      <description>EUVD-2026-38088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-38088</guid>
    </item>
    <item>
      <title>fkie_cve-2020-7663</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7663</link>
      <description>&lt;p&gt;websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-7663</guid>
    </item>
    <item>
      <title>GHSA-g6wq-qcwm-j5g2 — Regular Expression Denial of Service in websocket-extensions (RubyGem)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g6wq-qcwm-j5g2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: websocket-extensions&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The ReDoS flaw allows an attacker to exhaust the server&amp;#39;s capacity to process incoming requests by sending a WebSocket handshake request containing a header of the following form:&lt;/p&gt;
&lt;p&gt;Sec-WebSocket-Extensions: a; b=&amp;#34;\c\c\c\c\c\c\c\c\c\c ...&lt;/p&gt;
&lt;p&gt;That is, a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. The parser takes exponential time to reject this header as invalid, and this will block the processing of any other work on the same thread. Thus if you are running a single-threaded server, such a request can render your service completely unavailable.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Users should upgrade to version 0.1.5.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;There are no known work-arounds other than disabling any public-facing WebSocket functionality you are operating.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- https://blog.jcoglan.com/2020/06/02/redos-vulnerability-in-websocket-extensions/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: websocket-extensions&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The ReDoS flaw allows an attacker to exhaust the server&amp;#39;s capacity to process incoming requests by sending a WebSocket handshake request containing a header of the following form:&lt;/p&gt;
&lt;p&gt;Sec-WebSocket-Extensions: a; b=&amp;#34;\c\c\c\c\c\c\c\c\c\c ...&lt;/p&gt;
&lt;p&gt;That is, a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. The parser takes exponential time to reject this header as invalid, and this will block the processing of any other work on the same thread. Thus if you are running a single-threaded server, such a request can render your service completely unavailable.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Users should upgrade to version 0.1.5.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;There are no known work-arounds other than disabling any public-facing WebSocket functionality you are operating.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- https://blog.jcoglan.com/2020/06/02/redos-vulnerability-in-websocket-extensions/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g6wq-qcwm-j5g2</guid>
    </item>
    <item>
      <title>gsd-2020-7663</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-7663</link>
      <description>gsd-2020-7663</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-7663</guid>
    </item>
    <item>
      <title>OESA-2022-1553 — rubygem-websocket-extensions security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1553</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-websocket-extensions, openEuler:20.03-LTS-SP2: rubygem-websocket-extensions, openEuler:20.03-LTS-SP3: rubygem-websocket-extensions&lt;/p&gt;
&lt;p&gt;Generic extension manager for WebSocket connections.&#13;
&#13;
Security Fix(es):&#13;
&#13;
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.(CVE-2020-7663)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-websocket-extensions, openEuler:20.03-LTS-SP2: rubygem-websocket-extensions, openEuler:20.03-LTS-SP3: rubygem-websocket-extensions&lt;/p&gt;
&lt;p&gt;Generic extension manager for WebSocket connections.&#13;
&#13;
Security Fix(es):&#13;
&#13;
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.(CVE-2020-7663)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1553</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11357-1 — ruby2.7-rubygem-websocket-extensions-0.1.5-1.7 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11357-1</link>
      <description>&lt;p&gt;ruby2.7-rubygem-websocket-extensions-0.1.5-1.7 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby2.7-rubygem-websocket-extensions-0.1.5-1.7 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11357-1</guid>
    </item>
    <item>
      <title>RHSA-2020:4366 — Red Hat Security Advisory: Satellite 6.8 release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4366</link>
      <description>&lt;p&gt;mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018) puppet-agent: Puppet Agent does not properly verify SSL connection when downloading a CRL rack-protection: Timing attack in authenticity_token.rb hibernate-validator: safeHTML validator allows XSS Django: Incorrect HTTP detection with reverse-proxy connecting via HTTPS rubygem-rack: hijack sessions by using timing attacks targeting the session id rubygem-secure_headers: limited header injection when using dynamic overrides with user input rubygem-secure_headers: directive injection when using dynamic overrides with user input rubygem-actionview: views that use the `j` or `escape_javascript` methods are susceptible to XSS attacks netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling rubygem-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser puppet: Arbitrary catalog retrieval puppet: puppet server and puppetDB may leak sensitive information via metrics API rubygem-rack: directory traversal in Rack::Directory rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie names jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core hibernate-validator: Improper input validation in the interpolation of constraint error messages jackson-databind: Ser…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018) puppet-agent: Puppet Agent does not properly verify SSL connection when downloading a CRL rack-protection: Timing attack in authenticity_token.rb hibernate-validator: safeHTML validator allows XSS Django: Incorrect HTTP detection with reverse-proxy connecting via HTTPS rubygem-rack: hijack sessions by using timing attacks targeting the session id rubygem-secure_headers: limited header injection when using dynamic overrides with user input rubygem-secure_headers: directive injection when using dynamic overrides with user input rubygem-actionview: views that use the `j` or `escape_javascript` methods are susceptible to XSS attacks netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling rubygem-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser puppet: Arbitrary catalog retrieval puppet: puppet server and puppetDB may leak sensitive information via metrics API rubygem-rack: directory traversal in Rack::Directory rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie names jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core hibernate-validator: Improper input validation in the interpolation of constraint error messages jackson-databind: Ser…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4366</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:0127-1 — Security update for rubygem-websocket-extensions</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:0127-1</link>
      <description>&lt;p&gt;Security update for rubygem-websocket-extensions&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-websocket-extensions&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:0127-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-7663</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7663</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-websocket-extensions, Ubuntu:18.04:LTS: ruby-websocket-extensions, Ubuntu:20.04:LTS: ruby-websocket-extensions&lt;/p&gt;
&lt;p&gt;websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-websocket-extensions, Ubuntu:18.04:LTS: ruby-websocket-extensions, Ubuntu:20.04:LTS: ruby-websocket-extensions&lt;/p&gt;
&lt;p&gt;websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7663</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1087 — GitLab: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1087</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um einen Cross-Site Scripting oder Denial of Service Angriff durchzuführen, Sicherheitsmechanismen zu umgehen, Daten zu manipulieren oder vertrauliche Daten einzusehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um einen Cross-Site Scripting oder Denial of Service Angriff durchzuführen, Sicherheitsmechanismen zu umgehen, Daten zu manipulieren oder vertrauliche Daten einzusehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1087</guid>
    </item>
  </channel>
</rss>
