<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:43:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-07501</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-07501</link>
      <description>bdu:2022-07501</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-07501</guid>
    </item>
    <item>
      <title>BIT-tomcat-2022-42252 — Apache Tomcat request smuggling via malformed content-length</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2022-42252</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0 to 9.0.67, 10.0.0 to 10.0.26 or 10.1.0 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0 to 9.0.67, 10.0.0 to 10.0.26 or 10.1.0 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2022-42252</guid>
    </item>
    <item>
      <title>certfr-2022-avi-975 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un
attaquant de provoquer un contournement de la p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-975</link>
      <description>certfr-2022-avi-975</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-975</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AG86451 — Security fixes in tomcat9 9.0.68-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ag86451</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tomcat9&lt;/p&gt;
&lt;p&gt;Package tomcat9 version 9.0.68-r0 fixes 1 vulnerabilities: CVE-2022-42252&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tomcat9&lt;/p&gt;
&lt;p&gt;Package tomcat9 version 9.0.68-r0 fixes 1 vulnerabilities: CVE-2022-42252&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ag86451</guid>
    </item>
    <item>
      <title>EUVD-2026-237886</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237886</link>
      <description>EUVD-2026-237886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237886</guid>
    </item>
    <item>
      <title>fkie_cve-2022-42252</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-42252</link>
      <description>&lt;p&gt;If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-42252</guid>
    </item>
    <item>
      <title>GHSA-p22x-g9px-3945 — Apache Tomcat may reject request containing invalid Content-Length header</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p22x-g9px-3945</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.apache.tomcat:tomcat-coyote&lt;/p&gt;
&lt;p&gt;If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.apache.tomcat:tomcat-coyote&lt;/p&gt;
&lt;p&gt;If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p22x-g9px-3945</guid>
    </item>
    <item>
      <title>gsd-2022-42252</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-42252</link>
      <description>gsd-2022-42252</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-42252</guid>
    </item>
    <item>
      <title>OESA-2023-1058 — tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1058</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: tomcat, openEuler:20.03-LTS-SP3: tomcat, openEuler:22.03-LTS: tomcat, openEuler:22.03-LTS-SP1: tomcat&lt;/p&gt;
&lt;p&gt;The Apache Tomcat software is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. We invite you to participate in this open development project&#13;
&#13;
Security Fix(es):&#13;
&#13;
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.(CVE-2022-42252)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: tomcat, openEuler:20.03-LTS-SP3: tomcat, openEuler:22.03-LTS: tomcat, openEuler:22.03-LTS-SP1: tomcat&lt;/p&gt;
&lt;p&gt;The Apache Tomcat software is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. We invite you to participate in this open development project&#13;
&#13;
Security Fix(es):&#13;
&#13;
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.(CVE-2022-42252)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1058</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12534-1 — tomcat-9.0.43-11.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12534-1</link>
      <description>&lt;p&gt;tomcat-9.0.43-11.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat-9.0.43-11.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12534-1</guid>
    </item>
    <item>
      <title>RHSA-2023:1663 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.2 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1663</link>
      <description>&lt;p&gt;tomcat: request smuggling tomcat: JsonErrorReportValve injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: request smuggling tomcat: JsonErrorReportValve injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1663</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:4193-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:4193-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:4193-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-42252</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-42252</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-42252</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1918 — Apache Tomcat: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1918</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1918</guid>
    </item>
  </channel>
</rss>
