<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:45:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-01344</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01344</link>
      <description>bdu:2021-01344</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01344</guid>
    </item>
    <item>
      <title>BREW-mailcatcher-CVE-2020-8184 — Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names</title>
      <link>https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2020-8184</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mailcatcher&lt;/p&gt;
&lt;p&gt;A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;lt; 2.2.3, rack &amp;lt; 2.1.4 that makes it possible for an attacker to forge a secure or host-only cookie prefix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mailcatcher&lt;/p&gt;
&lt;p&gt;A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;lt; 2.2.3, rack &amp;lt; 2.1.4 that makes it possible for an attacker to forge a secure or host-only cookie prefix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2020-8184</guid>
    </item>
    <item>
      <title>cnvd-2020-52838</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-52838</link>
      <description>cnvd-2020-52838</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-52838</guid>
    </item>
    <item>
      <title>EUVD-2026-38303</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-38303</link>
      <description>EUVD-2026-38303</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-38303</guid>
    </item>
    <item>
      <title>fkie_cve-2020-8184</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8184</link>
      <description>&lt;p&gt;A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;lt; 2.2.3, rack &amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;lt; 2.2.3, rack &amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-8184</guid>
    </item>
    <item>
      <title>GHSA-j6w9-fv6q-3q52 — Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j6w9-fv6q-3q52</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rack&lt;/p&gt;
&lt;p&gt;A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;lt; 2.2.3, rack &amp;lt; 2.1.4 that makes it possible for an attacker to forge a secure or host-only cookie prefix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rack&lt;/p&gt;
&lt;p&gt;A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;lt; 2.2.3, rack &amp;lt; 2.1.4 that makes it possible for an attacker to forge a secure or host-only cookie prefix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j6w9-fv6q-3q52</guid>
    </item>
    <item>
      <title>gsd-2020-8184</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-8184</link>
      <description>gsd-2020-8184</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-8184</guid>
    </item>
    <item>
      <title>OESA-2022-1729 — rubygem-rack security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1729</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-rack, openEuler:20.03-LTS-SP3: rubygem-rack, openEuler:22.03-LTS: rubygem-rack&lt;/p&gt;
&lt;p&gt;Rack provides a minimal, modular, and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers,  web frameworks, and software in between (the so-called middleware) into  a single method call.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Denial of Service Vulnerability in Rack Multipart Parsing(CVE-2022-30122)&#13;
&#13;
Possible shell escape sequence injection vulnerability in Rack(CVE-2022-30123)&#13;
&#13;
A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;amp;lt; 2.2.3, rack &amp;amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.(CVE-2020-8184)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rubygem-rack, openEuler:20.03-LTS-SP3: rubygem-rack, openEuler:22.03-LTS: rubygem-rack&lt;/p&gt;
&lt;p&gt;Rack provides a minimal, modular, and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers,  web frameworks, and software in between (the so-called middleware) into  a single method call.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Denial of Service Vulnerability in Rack Multipart Parsing(CVE-2022-30122)&#13;
&#13;
Possible shell escape sequence injection vulnerability in Rack(CVE-2022-30123)&#13;
&#13;
A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;amp;lt; 2.2.3, rack &amp;amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.(CVE-2020-8184)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1729</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1993-1 — Security update for rmt-server</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1993-1</link>
      <description>&lt;p&gt;Security update for rmt-server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rmt-server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1993-1</guid>
    </item>
    <item>
      <title>RHSA-2020:4366 — Red Hat Security Advisory: Satellite 6.8 release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4366</link>
      <description>&lt;p&gt;mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018) puppet-agent: Puppet Agent does not properly verify SSL connection when downloading a CRL rack-protection: Timing attack in authenticity_token.rb hibernate-validator: safeHTML validator allows XSS Django: Incorrect HTTP detection with reverse-proxy connecting via HTTPS rubygem-rack: hijack sessions by using timing attacks targeting the session id rubygem-secure_headers: limited header injection when using dynamic overrides with user input rubygem-secure_headers: directive injection when using dynamic overrides with user input rubygem-actionview: views that use the `j` or `escape_javascript` methods are susceptible to XSS attacks netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling rubygem-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser puppet: Arbitrary catalog retrieval puppet: puppet server and puppetDB may leak sensitive information via metrics API rubygem-rack: directory traversal in Rack::Directory rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie names jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core hibernate-validator: Improper input validation in the interpolation of constraint error messages jackson-databind: Ser…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018) puppet-agent: Puppet Agent does not properly verify SSL connection when downloading a CRL rack-protection: Timing attack in authenticity_token.rb hibernate-validator: safeHTML validator allows XSS Django: Incorrect HTTP detection with reverse-proxy connecting via HTTPS rubygem-rack: hijack sessions by using timing attacks targeting the session id rubygem-secure_headers: limited header injection when using dynamic overrides with user input rubygem-secure_headers: directive injection when using dynamic overrides with user input rubygem-actionview: views that use the `j` or `escape_javascript` methods are susceptible to XSS attacks netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling rubygem-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser puppet: Arbitrary catalog retrieval puppet: puppet server and puppetDB may leak sensitive information via metrics API rubygem-rack: directory traversal in Rack::Directory rubygem-rack: percent-encoded cookies can be used to overwrite existing prefixed cookie names jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core hibernate-validator: Improper input validation in the interpolation of constraint error messages jackson-databind: Ser…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4366</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:2678-1 — Security update for rubygem-rack</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:2678-1</link>
      <description>&lt;p&gt;Security update for rubygem-rack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-rack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:2678-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-8184</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8184</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ruby-rack, Ubuntu:16.04:LTS: ruby-rack, Ubuntu:18.04:LTS: ruby-rack, Ubuntu:20.04:LTS: ruby-rack&lt;/p&gt;
&lt;p&gt;A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;lt; 2.2.3, rack &amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ruby-rack, Ubuntu:16.04:LTS: ruby-rack, Ubuntu:18.04:LTS: ruby-rack, Ubuntu:20.04:LTS: ruby-rack&lt;/p&gt;
&lt;p&gt;A reliance on cookies without validation/integrity check security vulnerability exists in rack &amp;lt; 2.2.3, rack &amp;lt; 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8184</guid>
    </item>
  </channel>
</rss>
