<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:52:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-08648</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08648</link>
      <description>bdu:2023-08648</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08648</guid>
    </item>
    <item>
      <title>certfr-2022-avi-366 — De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft.
Certaines d'entre elles permettent à un attaqua…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-366</link>
      <description>certfr-2022-avi-366</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-366</guid>
    </item>
    <item>
      <title>EUVD-2026-32665</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-32665</link>
      <description>EUVD-2026-32665</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-32665</guid>
    </item>
    <item>
      <title>fkie_cve-2021-43797</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43797</link>
      <description>&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to &amp;#34;sanitize&amp;#34; header names before it forward these to another remote system when used as proxy. This remote system can&amp;#39;t see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to &amp;#34;sanitize&amp;#34; header names before it forward these to another remote system when used as proxy. This remote system can&amp;#39;t see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-43797</guid>
    </item>
    <item>
      <title>GHSA-wx5j-54mm-rqqq — HTTP request smuggling in netty</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wx5j-54mm-rqqq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http, Maven: org.jboss.netty:netty, Maven: io.netty:netty&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Netty currently just skips control chars when these are present at the beginning / end of the header name. We should better fail fast as these are not allowed by the spec and could lead to HTTP request smuggling.&lt;/p&gt;
&lt;p&gt;Failing to do the validation might cause netty to &amp;#34;sanitize&amp;#34; header names before it forward these to another remote system when used as proxy. This remote system can&amp;#39;t see the invalid usage anymore and so not do the validation itself.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http, Maven: org.jboss.netty:netty, Maven: io.netty:netty&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Netty currently just skips control chars when these are present at the beginning / end of the header name. We should better fail fast as these are not allowed by the spec and could lead to HTTP request smuggling.&lt;/p&gt;
&lt;p&gt;Failing to do the validation might cause netty to &amp;#34;sanitize&amp;#34; header names before it forward these to another remote system when used as proxy. This remote system can&amp;#39;t see the invalid usage anymore and so not do the validation itself.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wx5j-54mm-rqqq</guid>
    </item>
    <item>
      <title>gsd-2021-43797</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-43797</link>
      <description>gsd-2021-43797</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-43797</guid>
    </item>
    <item>
      <title>OESA-2021-1472 — netty security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1472</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: netty, openEuler:20.03-LTS-SP2: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients. %package    help Summary:          Documents for  Buildarch:        noarch Requires:         man info Provides:         -javadoc = - Obsoletes:        -javadoc &amp;amp;lt; - %description help Man pages and other related documents for .&#13;
&#13;
Security Fix(es):&#13;
&#13;
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients. Netty prior to version 4.1.7.1.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to &amp;amp;quot;sanitize&amp;amp;quot; header names before it forward these to another remote system when used as proxy. This remote system can&amp;amp;apos;t see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.7.1.Final to receive a patch.(CVE-2021-43797)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: netty, openEuler:20.03-LTS-SP2: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients. %package    help Summary:          Documents for  Buildarch:        noarch Requires:         man info Provides:         -javadoc = - Obsoletes:        -javadoc &amp;amp;lt; - %description help Man pages and other related documents for .&#13;
&#13;
Security Fix(es):&#13;
&#13;
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp;amp; clients. Netty prior to version 4.1.7.1.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to &amp;amp;quot;sanitize&amp;amp;quot; header names before it forward these to another remote system when used as proxy. This remote system can&amp;amp;apos;t see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.7.1.Final to receive a patch.(CVE-2021-43797)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1472</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11743-1 — netty-4.1.72-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11743-1</link>
      <description>&lt;p&gt;netty-4.1.72-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-4.1.72-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11743-1</guid>
    </item>
    <item>
      <title>RHSA-2022:0520 — Red Hat Security Advisory: Red Hat Data Grid 8.3.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0520</link>
      <description>&lt;p&gt;wildfly-elytron: possible timing attack in ScramServer XStream: remote command execution attack by manipulating the processed input stream netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way xstream: Arbitrary code execution via unsafe deserialization of Xalan xsltc.trax.TemplatesImpl xstream: Infinite loop DoS via unsafe deserialization of sun.reflect.annotation.AnnotationInvocationHandler xstream: Arbitrary code execution via unsafe deserialization of com.sun.xml.internal.ws.client.sei.* xstream: Arbitrary code execution via unsafe deserialization of sun.tracing.* xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.ldap.LdapBindingEnumeration xstream: Arbitrary code execution via unsafe deserialization of javax.swing.UIDefaults$ProxyLazyValue xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.ldap.LdapSearchEnumeration xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.toolkit.dir.ContextEnumerator xstream: Arbitrary code execution via unsafe deserialization of com.sun.corba.* xstream: Server-side request forgery (SSRF) via unsafe deserialization of com.sun.xml.internal.ws.client.sei.* xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.ldap.LdapBindingEnumeration xstream: Server-side request forgery (SSRF) via unsafe deser…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;wildfly-elytron: possible timing attack in ScramServer XStream: remote command execution attack by manipulating the processed input stream netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way xstream: Arbitrary code execution via unsafe deserialization of Xalan xsltc.trax.TemplatesImpl xstream: Infinite loop DoS via unsafe deserialization of sun.reflect.annotation.AnnotationInvocationHandler xstream: Arbitrary code execution via unsafe deserialization of com.sun.xml.internal.ws.client.sei.* xstream: Arbitrary code execution via unsafe deserialization of sun.tracing.* xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.ldap.LdapBindingEnumeration xstream: Arbitrary code execution via unsafe deserialization of javax.swing.UIDefaults$ProxyLazyValue xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.ldap.LdapSearchEnumeration xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.toolkit.dir.ContextEnumerator xstream: Arbitrary code execution via unsafe deserialization of com.sun.corba.* xstream: Server-side request forgery (SSRF) via unsafe deserialization of com.sun.xml.internal.ws.client.sei.* xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.ldap.LdapBindingEnumeration xstream: Server-side request forgery (SSRF) via unsafe deser…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0520</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:1271-1 — Security update for netty</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:1271-1</link>
      <description>&lt;p&gt;Security update for netty&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for netty&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:1271-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-43797</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43797</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to &amp;#34;sanitize&amp;#34; header names before it forward these to another remote system when used as proxy. This remote system can&amp;#39;t see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp;amp; clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to &amp;#34;sanitize&amp;#34; header names before it forward these to another remote system when used as proxy. This remote system can&amp;#39;t see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43797</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</guid>
    </item>
  </channel>
</rss>
