<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:58:23 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03688</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03688</link>
      <description>bdu:2021-03688</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03688</guid>
    </item>
    <item>
      <title>BIT-tomcat-2021-33037 — Incorrect Transfer-Encoding handling with HTTP/1.0</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2021-33037</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Apache Tomcat 10.0.0 to 10.0.6, 9.0.0 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Apache Tomcat 10.0.0 to 10.0.6, 9.0.0 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2021-33037</guid>
    </item>
    <item>
      <title>certfr-2021-avi-801 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL.
Certaines d'entre elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-801</link>
      <description>certfr-2021-avi-801</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-801</guid>
    </item>
    <item>
      <title>EUVD-2026-28257</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-28257</link>
      <description>EUVD-2026-28257</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-28257</guid>
    </item>
    <item>
      <title>fkie_cve-2021-33037</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-33037</link>
      <description>&lt;p&gt;Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-33037</guid>
    </item>
    <item>
      <title>GHSA-4vww-mc66-62m6 — HTTP Request Smuggling in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4vww-mc66-62m6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4vww-mc66-62m6</guid>
    </item>
    <item>
      <title>gsd-2021-33037</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-33037</link>
      <description>gsd-2021-33037</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-33037</guid>
    </item>
    <item>
      <title>OESA-2021-1275 — tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1275</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: tomcat, openEuler:20.03-LTS-SP2: tomcat&lt;/p&gt;
&lt;p&gt;The Apache Tomcat software is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. We invite you to participate in this open development project&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.(CVE-2021-33037)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: tomcat, openEuler:20.03-LTS-SP2: tomcat&lt;/p&gt;
&lt;p&gt;The Apache Tomcat software is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. We invite you to participate in this open development project&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.(CVE-2021-33037)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1275</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1490-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1490-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1490-1</guid>
    </item>
    <item>
      <title>RHSA-2021:4861 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.6.0 Security release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:4861</link>
      <description>&lt;p&gt;openssl: Read buffer overruns processing ASN.1 strings openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash() tomcat: JNDI realm authentication weakness tomcat: HTTP request smuggling when used with a reverse proxy tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: Read buffer overruns processing ASN.1 strings openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash() tomcat: JNDI realm authentication weakness tomcat: HTTP request smuggling when used with a reverse proxy tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:4861</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:3602-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:3602-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:3602-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-33037</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33037</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat6, Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:20.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat6, Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:20.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33037</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</guid>
    </item>
  </channel>
</rss>
