<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:38:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-00183</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00183</link>
      <description>bdu:2024-00183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00183</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0337 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0337</link>
      <description>certfr-2023-avi-0337</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0337</guid>
    </item>
    <item>
      <title>EUVD-2026-232487</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232487</link>
      <description>EUVD-2026-232487</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232487</guid>
    </item>
    <item>
      <title>fkie_cve-2022-41915</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41915</link>
      <description>&lt;p&gt;Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator&amp;lt;?&amp;gt;)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator&amp;lt;?&amp;gt;)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-41915</guid>
    </item>
    <item>
      <title>GHSA-hh82-3pmq-7frp — Netty vulnerable to HTTP Response splitting from assigning header value iterator</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hh82-3pmq-7frp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http&lt;/p&gt;
&lt;p&gt;### Impact
When calling `DefaultHttpHeaders.set` with an _iterator_ of values (as opposed to a single given value), header value validation was not performed, allowing malicious header values in the iterator to perform [HTTP Response Splitting](https://owasp.org/www-community/attacks/HTTP_Response_Splitting).&lt;/p&gt;
&lt;p&gt;### Patches
The necessary validation was added in Netty 4.1.86.Final.&lt;/p&gt;
&lt;p&gt;### Workarounds
Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator&amp;lt;?&amp;gt;)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.&lt;/p&gt;
&lt;p&gt;### References
[HTTP Response Splitting](https://owasp.org/www-community/attacks/HTTP_Response_Splitting)
[CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers](https://cwe.mitre.org/data/definitions/113.html)&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [[example link to repo](https://github.com/netty/netty)](https://github.com/netty/netty)
* Email us at [netty-security@googlegroups.com](mailto:netty-security@googlegroups.com)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.netty:netty-codec-http&lt;/p&gt;
&lt;p&gt;### Impact
When calling `DefaultHttpHeaders.set` with an _iterator_ of values (as opposed to a single given value), header value validation was not performed, allowing malicious header values in the iterator to perform [HTTP Response Splitting](https://owasp.org/www-community/attacks/HTTP_Response_Splitting).&lt;/p&gt;
&lt;p&gt;### Patches
The necessary validation was added in Netty 4.1.86.Final.&lt;/p&gt;
&lt;p&gt;### Workarounds
Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator&amp;lt;?&amp;gt;)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.&lt;/p&gt;
&lt;p&gt;### References
[HTTP Response Splitting](https://owasp.org/www-community/attacks/HTTP_Response_Splitting)
[CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers](https://cwe.mitre.org/data/definitions/113.html)&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [[example link to repo](https://github.com/netty/netty)](https://github.com/netty/netty)
* Email us at [netty-security@googlegroups.com](mailto:netty-security@googlegroups.com)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hh82-3pmq-7frp</guid>
    </item>
    <item>
      <title>gsd-2022-41915</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-41915</link>
      <description>gsd-2022-41915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-41915</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14442-1 — netty-4.1.114-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14442-1</link>
      <description>&lt;p&gt;netty-4.1.114-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-4.1.114-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14442-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:2096-2 — Security update for netty, netty-tcnative</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:2096-2</link>
      <description>&lt;p&gt;Security update for netty, netty-tcnative&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for netty, netty-tcnative&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:2096-2</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-41915</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41915</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: netty, Ubuntu:16.04:LTS: netty-3.9, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:18.04:LTS: netty-3.9, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator&amp;lt;?&amp;gt;)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: netty, Ubuntu:16.04:LTS: netty-3.9, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:18.04:LTS: netty-3.9, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty&lt;/p&gt;
&lt;p&gt;Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator&amp;lt;?&amp;gt;)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41915</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0091 — NetApp ActiveIQ Unified Manager: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0091</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in NetApp ActiveIQ Unified Manager ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen und um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in NetApp ActiveIQ Unified Manager ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen und um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0091</guid>
    </item>
  </channel>
</rss>
