<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:45:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-236767</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-236767</link>
      <description>EUVD-2026-236767</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-236767</guid>
    </item>
    <item>
      <title>fkie_cve-2023-28362</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28362</link>
      <description>&lt;p&gt;The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-28362</guid>
    </item>
    <item>
      <title>GHSA-4g8v-vg43-wpgf — Actionpack has possible cross-site scripting vulnerability via User Supplied Values to redirect_to</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4g8v-vg43-wpgf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: actionpack&lt;/p&gt;
&lt;p&gt;The `redirect_to` method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header. This vulnerability has been assigned the CVE identifier CVE-2023-28362.&lt;/p&gt;
&lt;p&gt;Versions Affected: All. Not affected: None Fixed Versions: 7.0.5.1, 6.1.7.4&lt;/p&gt;
&lt;p&gt;# Impact&lt;/p&gt;
&lt;p&gt;This introduces the potential for a Cross-site-scripting (XSS) payload to be delivered on the now static redirection page. Note that this both requires user interaction and for a Rails app to be configured to allow redirects to external hosts (defaults to false in Rails &amp;gt;= 7.0.x).&lt;/p&gt;
&lt;p&gt;# Releases&lt;/p&gt;
&lt;p&gt;The FIXED releases are available at the normal locations.&lt;/p&gt;
&lt;p&gt;# Workarounds&lt;/p&gt;
&lt;p&gt;Avoid providing user supplied URLs with arbitrary schemes to the `redirect_to` method.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: actionpack&lt;/p&gt;
&lt;p&gt;The `redirect_to` method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header. This vulnerability has been assigned the CVE identifier CVE-2023-28362.&lt;/p&gt;
&lt;p&gt;Versions Affected: All. Not affected: None Fixed Versions: 7.0.5.1, 6.1.7.4&lt;/p&gt;
&lt;p&gt;# Impact&lt;/p&gt;
&lt;p&gt;This introduces the potential for a Cross-site-scripting (XSS) payload to be delivered on the now static redirection page. Note that this both requires user interaction and for a Rails app to be configured to allow redirects to external hosts (defaults to false in Rails &amp;gt;= 7.0.x).&lt;/p&gt;
&lt;p&gt;# Releases&lt;/p&gt;
&lt;p&gt;The FIXED releases are available at the normal locations.&lt;/p&gt;
&lt;p&gt;# Workarounds&lt;/p&gt;
&lt;p&gt;Avoid providing user supplied URLs with arbitrary schemes to the `redirect_to` method.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4g8v-vg43-wpgf</guid>
    </item>
    <item>
      <title>gsd-2023-28362</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-28362</link>
      <description>gsd-2023-28362</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-28362</guid>
    </item>
    <item>
      <title>OESA-2024-2465 — rubygem-actionpack security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2465</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: rubygem-actionpack&lt;/p&gt;
&lt;p&gt;Eases web-request routing, handling, and response as a half-way front, half-way page controller. Implemented with specific emphasis on enabling easy unit/integration testing that doesn&amp;amp;apos;t require a browser.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A Cross-site Scripting (XSS) vulnerability was found in Actionpack due to improper sanitization of user-supplied values. This allows provided values to contain characters that are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned location header.(CVE-2023-28362)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: rubygem-actionpack&lt;/p&gt;
&lt;p&gt;Eases web-request routing, handling, and response as a half-way front, half-way page controller. Implemented with specific emphasis on enabling easy unit/integration testing that doesn&amp;amp;apos;t require a browser.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A Cross-site Scripting (XSS) vulnerability was found in Actionpack due to improper sanitization of user-supplied values. This allows provided values to contain characters that are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned location header.(CVE-2023-28362)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2465</guid>
    </item>
    <item>
      <title>RHSA-2023:7851 — Red Hat Security Advisory: Satellite 6.14.1 Async Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:7851</link>
      <description>&lt;p&gt;foreman: World readable file containing secrets actionpack: Possible XSS via User Supplied Values to redirect_to GitPython: Blind local file inclusion python-urllib3: Cookie request header isn&amp;#39;t stripped during cross-origin redirects urllib3: Request body not stripped after redirect from 303 status changes request method to GET&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;foreman: World readable file containing secrets actionpack: Possible XSS via User Supplied Values to redirect_to GitPython: Blind local file inclusion python-urllib3: Cookie request header isn&amp;#39;t stripped during cross-origin redirects urllib3: Request body not stripped after redirect from 303 status changes request method to GET&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:7851</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:3229-1 — Security update for rubygem-actionpack-5_1</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:3229-1</link>
      <description>&lt;p&gt;Security update for rubygem-actionpack-5_1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-actionpack-5_1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:3229-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-28362</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28362</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28362</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1577 — Ruby on Rails: Schwachstelle ermöglicht Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1577</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby on Rails ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby on Rails ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1577</guid>
    </item>
  </channel>
</rss>
