<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:31:12 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:4791 — Moderate: python39:3.9 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:4791</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python39, AlmaLinux:8: python39-PyMySQL, AlmaLinux:8: python39-cffi, AlmaLinux:8: python39-chardet, AlmaLinux:8: python39-cryptography, AlmaLinux:8: python39-devel, AlmaLinux:8: python39-idle, AlmaLinux:8: python39-idna, AlmaLinux:8: python39-libs, AlmaLinux:8: python39-lxml and 26 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mod_wsgi: Trusted Proxy Headers Removing Bypass (CVE-2022-2255)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python39, AlmaLinux:8: python39-PyMySQL, AlmaLinux:8: python39-cffi, AlmaLinux:8: python39-chardet, AlmaLinux:8: python39-cryptography, AlmaLinux:8: python39-devel, AlmaLinux:8: python39-idle, AlmaLinux:8: python39-idna, AlmaLinux:8: python39-libs, AlmaLinux:8: python39-lxml and 26 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mod_wsgi: Trusted Proxy Headers Removing Bypass (CVE-2022-2255)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:4791</guid>
    </item>
    <item>
      <title>bdu:2022-05209</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05209</link>
      <description>bdu:2022-05209</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05209</guid>
    </item>
    <item>
      <title>BIT-mod_wsgi-2022-2255</title>
      <link>https://cve.radiocsirt.org/vuln/bit-mod_wsgi-2022-2255</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mod_wsgi&lt;/p&gt;
&lt;p&gt;A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mod_wsgi&lt;/p&gt;
&lt;p&gt;A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-mod_wsgi-2022-2255</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0218 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218</link>
      <description>certfr-2026-avi-0218</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218</guid>
    </item>
    <item>
      <title>EUVD-2026-12290</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-12290</link>
      <description>EUVD-2026-12290</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-12290</guid>
    </item>
    <item>
      <title>fkie_cve-2022-2255</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2255</link>
      <description>&lt;p&gt;A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-2255</guid>
    </item>
    <item>
      <title>GHSA-7527-8855-9cf8 — Incorrect header handling in mod-wsgi</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7527-8855-9cf8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mod-wsgi&lt;/p&gt;
&lt;p&gt;A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mod-wsgi&lt;/p&gt;
&lt;p&gt;A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7527-8855-9cf8</guid>
    </item>
    <item>
      <title>gsd-2022-2255</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-2255</link>
      <description>gsd-2022-2255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-2255</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-2255 — A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy all…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-2255</link>
      <description>msrc_CVE-2022-2255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-2255</guid>
    </item>
    <item>
      <title>OESA-2022-1827 — mod_wsgi security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1827</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: mod_wsgi, openEuler:20.03-LTS-SP3: mod_wsgi, openEuler:22.03-LTS: mod_wsgi&lt;/p&gt;
&lt;p&gt;The mod_wsgi adapter is an Apache module that provides a WSGI compliant interface for hosting Python based web applications within Apache. The adapter is written completely in C code against the Apache C runtime andfor hosting WSGI applications within Apache has a lower overhead than using existing WSGI adapters for mod_python or CGI.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy (trusted proxies are configured via the WSGITrustedProxies directive) allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&#13;
&#13;
References:
https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L13940-L13941
https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L14046-L14082(CVE-2022-2255)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: mod_wsgi, openEuler:20.03-LTS-SP3: mod_wsgi, openEuler:22.03-LTS: mod_wsgi&lt;/p&gt;
&lt;p&gt;The mod_wsgi adapter is an Apache module that provides a WSGI compliant interface for hosting Python based web applications within Apache. The adapter is written completely in C code against the Apache C runtime andfor hosting WSGI applications within Apache has a lower overhead than using existing WSGI adapters for mod_python or CGI.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy (trusted proxies are configured via the WSGITrustedProxies directive) allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&#13;
&#13;
References:
https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L13940-L13941
https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L14046-L14082(CVE-2022-2255)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1827</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12535-1 — apache2-mod_wsgi-4.9.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12535-1</link>
      <description>&lt;p&gt;apache2-mod_wsgi-4.9.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache2-mod_wsgi-4.9.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12535-1</guid>
    </item>
    <item>
      <title>PYSEC-2022-254</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2022-254</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mod-wsgi&lt;/p&gt;
&lt;p&gt;A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mod-wsgi&lt;/p&gt;
&lt;p&gt;A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2022-254</guid>
    </item>
    <item>
      <title>RHSA-2025:4791 — Red Hat Security Advisory: python39:3.9 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:4791</link>
      <description>&lt;p&gt;mod_wsgi: Trusted Proxy Headers Removing Bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mod_wsgi: Trusted Proxy Headers Removing Bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:4791</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:4013-1 — Security update for apache2-mod_wsgi</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:4013-1</link>
      <description>&lt;p&gt;Security update for apache2-mod_wsgi&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2-mod_wsgi&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:4013-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-2255</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2255</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mod-wsgi, Ubuntu:20.04:LTS: mod-wsgi, Ubuntu:22.04:LTS: mod-wsgi&lt;/p&gt;
&lt;p&gt;A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mod-wsgi, Ubuntu:20.04:LTS: mod-wsgi, Ubuntu:22.04:LTS: mod-wsgi&lt;/p&gt;
&lt;p&gt;A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2255</guid>
    </item>
  </channel>
</rss>
