<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:23:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00310</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00310</link>
      <description>bdu:2022-00310</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00310</guid>
    </item>
    <item>
      <title>certfr-2021-avi-407 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-407</link>
      <description>certfr-2021-avi-407</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-407</guid>
    </item>
    <item>
      <title>EUVD-2026-22135</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-22135</link>
      <description>EUVD-2026-22135</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-22135</guid>
    </item>
    <item>
      <title>fkie_cve-2021-21290</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-21290</link>
      <description>&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method &amp;#34;File.createTempFile&amp;#34; on unix-like systems creates a random file, but, by default will create this file with the permissions &amp;#34;-rw-r--r--&amp;#34;. Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty&amp;#39;s &amp;#34;AbstractDiskHttpData&amp;#34; is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own &amp;#34;java.io.tmpdir&amp;#34; when you start the JVM or use &amp;#34;DefaultHttpDataFactory.setBaseDir(...)&amp;#34; to set the directory to something that is only readable by the current user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method &amp;#34;File.createTempFile&amp;#34; on unix-like systems creates a random file, but, by default will create this file with the permissions &amp;#34;-rw-r--r--&amp;#34;. Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty&amp;#39;s &amp;#34;AbstractDiskHttpData&amp;#34; is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own &amp;#34;java.io.tmpdir&amp;#34; when you start the JVM or use &amp;#34;DefaultHttpDataFactory.setBaseDir(...)&amp;#34; to set the directory to something that is only readable by the current user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-21290</guid>
    </item>
    <item>
      <title>GHSA-5mcr-gq6c-3hq2 — Local Information Disclosure Vulnerability in Netty on Unix-Like systems</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5mcr-gq6c-3hq2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http, Maven: org.jboss.netty:netty, Maven: io.netty:netty&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled.&lt;/p&gt;
&lt;p&gt;The CVSSv3.1 score of this vulnerability is calculated to be a [6.2/10](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&amp;amp;version=3.1)&lt;/p&gt;
&lt;p&gt;### Vulnerability Details&lt;/p&gt;
&lt;p&gt;On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems.&lt;/p&gt;
&lt;p&gt;The method `File.createTempFile` on unix-like systems creates a random file, but, by default will create this file with the permissions `-rw-r--r--`. Thus, if sensitive information is written to this file, other local users can read this information.&lt;/p&gt;
&lt;p&gt;This is the case in netty&amp;#39;s `AbstractDiskHttpData` is vulnerable.&lt;/p&gt;
&lt;p&gt;https://github.com/netty/netty/blob/e5951d46fc89db507ba7d2968d2ede26378f0b04/codec-http/src/main/java/io/netty/handler/codec/http/multipart/AbstractDiskHttpData.java#L80-L101&lt;/p&gt;
&lt;p&gt;`AbstractDiskHttpData` is used as a part of the `DefaultHttpDataFactory` class which is used by `HttpPostRequestDecoder` / `HttpPostMultiPartRequestDecoder`.&lt;/p&gt;
&lt;p&gt;You may be affected by this vulnerability your project contains the following code patterns:&lt;/p&gt;
&lt;p&gt;```java
channelPipeline.addLast(new HttpPostRequestDecoder(...));
```&lt;/p&gt;
&lt;p&gt;```java…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http, Maven: org.jboss.netty:netty, Maven: io.netty:netty&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled.&lt;/p&gt;
&lt;p&gt;The CVSSv3.1 score of this vulnerability is calculated to be a [6.2/10](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&amp;amp;version=3.1)&lt;/p&gt;
&lt;p&gt;### Vulnerability Details&lt;/p&gt;
&lt;p&gt;On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems.&lt;/p&gt;
&lt;p&gt;The method `File.createTempFile` on unix-like systems creates a random file, but, by default will create this file with the permissions `-rw-r--r--`. Thus, if sensitive information is written to this file, other local users can read this information.&lt;/p&gt;
&lt;p&gt;This is the case in netty&amp;#39;s `AbstractDiskHttpData` is vulnerable.&lt;/p&gt;
&lt;p&gt;https://github.com/netty/netty/blob/e5951d46fc89db507ba7d2968d2ede26378f0b04/codec-http/src/main/java/io/netty/handler/codec/http/multipart/AbstractDiskHttpData.java#L80-L101&lt;/p&gt;
&lt;p&gt;`AbstractDiskHttpData` is used as a part of the `DefaultHttpDataFactory` class which is used by `HttpPostRequestDecoder` / `HttpPostMultiPartRequestDecoder`.&lt;/p&gt;
&lt;p&gt;You may be affected by this vulnerability your project contains the following code patterns:&lt;/p&gt;
&lt;p&gt;```java
channelPipeline.addLast(new HttpPostRequestDecoder(...));
```&lt;/p&gt;
&lt;p&gt;```java…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5mcr-gq6c-3hq2</guid>
    </item>
    <item>
      <title>gsd-2021-21290</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-21290</link>
      <description>gsd-2021-21290</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-21290</guid>
    </item>
    <item>
      <title>OESA-2021-1143 — netty security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1143</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty&amp;amp;apos;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method &amp;amp;quot;File.createTempFile&amp;amp;quot; on unix-like systems creates a random file, but, by default will create this file with the permissions &amp;amp;quot;-rw-r--r--&amp;amp;quot;. Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty&amp;amp;apos;s &amp;amp;quot;AbstractDiskHttpData&amp;amp;quot; is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own &amp;amp;quot;java.io.tmpdir&amp;amp;quot; when you start the JVM or use &amp;amp;quot;DefaultHttpDataFactory.setBaseDir(...)&amp;amp;quot; to set the directory to something…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty&amp;amp;apos;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method &amp;amp;quot;File.createTempFile&amp;amp;quot; on unix-like systems creates a random file, but, by default will create this file with the permissions &amp;amp;quot;-rw-r--r--&amp;amp;quot;. Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty&amp;amp;apos;s &amp;amp;quot;AbstractDiskHttpData&amp;amp;quot; is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own &amp;amp;quot;java.io.tmpdir&amp;amp;quot; when you start the JVM or use &amp;amp;quot;DefaultHttpDataFactory.setBaseDir(...)&amp;amp;quot; to set the directory to something…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1143</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11085-1 — netty-4.1.60-1.4 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11085-1</link>
      <description>&lt;p&gt;netty-4.1.60-1.4 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-4.1.60-1.4 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11085-1</guid>
    </item>
    <item>
      <title>RHSA-2021:0943 — Red Hat Security Advisory: Red Hat build of Eclipse Vert.x 4.0.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0943</link>
      <description>&lt;p&gt;netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0943</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:1271-1 — Security update for netty</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:1271-1</link>
      <description>&lt;p&gt;Security update for netty&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for netty&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:1271-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-21290</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-21290</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method &amp;#34;File.createTempFile&amp;#34; on unix-like systems creates a random file, but, by default will create this file with the permissions &amp;#34;-rw-r--r--&amp;#34;. Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty&amp;#39;s &amp;#34;AbstractDiskHttpData&amp;#34; is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own &amp;#34;java.io.tmpdir&amp;#34; when you start the JVM or use &amp;#34;DefaultHttpDataFactory.setBaseDir(...)&amp;#34; to set the directory to something that is only readable by the current user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty&amp;#39;s multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method &amp;#34;File.createTempFile&amp;#34; on unix-like systems creates a random file, but, by default will create this file with the permissions &amp;#34;-rw-r--r--&amp;#34;. Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty&amp;#39;s &amp;#34;AbstractDiskHttpData&amp;#34; is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own &amp;#34;java.io.tmpdir&amp;#34; when you start the JVM or use &amp;#34;DefaultHttpDataFactory.setBaseDir(...)&amp;#34; to set the directory to something that is only readable by the current user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-21290</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0567 — Red Hat OpenShift: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0567</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0567</guid>
    </item>
  </channel>
</rss>
