<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:10:59 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00315</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00315</link>
      <description>bdu:2022-00315</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00315</guid>
    </item>
    <item>
      <title>certfr-2021-avi-407 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-407</link>
      <description>certfr-2021-avi-407</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-407</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</guid>
    </item>
    <item>
      <title>EUVD-2026-22229</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-22229</link>
      <description>EUVD-2026-22229</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-22229</guid>
    </item>
    <item>
      <title>fkie_cve-2021-21409</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-21409</link>
      <description>&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-21409</guid>
    </item>
    <item>
      <title>GHSA-f256-j965-7f32 — Possible request smuggling in HTTP/2 due missing validation of content-length</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f256-j965-7f32</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http2, Maven: org.jboss.netty:netty, Maven: io.netty:netty&lt;/p&gt;
&lt;p&gt;### Impact
The content-length header is not correctly validated if the request only use a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1&lt;/p&gt;
&lt;p&gt;This is a followup of https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpj which did miss to fix this one case.&lt;/p&gt;
&lt;p&gt;### Patches
This was fixed as part of 4.1.61.Final&lt;/p&gt;
&lt;p&gt;### Workarounds
Validation can be done by the user before proxy the request by validating the header.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http2, Maven: org.jboss.netty:netty, Maven: io.netty:netty&lt;/p&gt;
&lt;p&gt;### Impact
The content-length header is not correctly validated if the request only use a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1&lt;/p&gt;
&lt;p&gt;This is a followup of https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpj which did miss to fix this one case.&lt;/p&gt;
&lt;p&gt;### Patches
This was fixed as part of 4.1.61.Final&lt;/p&gt;
&lt;p&gt;### Workarounds
Validation can be done by the user before proxy the request by validating the header.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f256-j965-7f32</guid>
    </item>
    <item>
      <title>gsd-2021-21409</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-21409</link>
      <description>gsd-2021-21409</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-21409</guid>
    </item>
    <item>
      <title>OESA-2021-1161 — netty security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1161</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients. %package    help Summary:          Documents for %{name} Buildarch:        noarch Requires:         man info Provides:         %{name}-javadoc = %{version}-%{release} Obsoletes:        %{name}-javadoc &amp;amp;lt; %{version}-%{release} %description help Man pages and other related documents for %{name}.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel&amp;amp;apos;s pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Content-Length now has…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients. %package    help Summary:          Documents for %{name} Buildarch:        noarch Requires:         man info Provides:         %{name}-javadoc = %{version}-%{release} Obsoletes:        %{name}-javadoc &amp;amp;lt; %{version}-%{release} %description help Man pages and other related documents for %{name}.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel&amp;amp;apos;s pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Content-Length now has…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1161</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14442-1 — netty-4.1.114-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14442-1</link>
      <description>&lt;p&gt;netty-4.1.114-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-4.1.114-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14442-1</guid>
    </item>
    <item>
      <title>RHSA-2021:1511 — Red Hat Security Advisory: AMQ Clients 2.9.1 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1511</link>
      <description>&lt;p&gt;netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation netty: Request smuggling via content-length header&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation netty: Request smuggling via content-length header&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1511</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:1315-1 — Security update for netty</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:1315-1</link>
      <description>&lt;p&gt;Security update for netty&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for netty&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:1315-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-21409</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-21409</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-21409</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0809 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</guid>
    </item>
  </channel>
</rss>
