<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:41:27 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02173</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02173</link>
      <description>bdu:2024-02173</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02173</guid>
    </item>
    <item>
      <title>BREW-airshare-CVE-2023-47627 — AIOHTTP has problems in HTTP parser (the python one, not llhttp)</title>
      <link>https://cve.radiocsirt.org/vuln/brew-airshare-cve-2023-47627</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: airshare&lt;/p&gt;
&lt;p&gt;# Summary
The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling.
This parser is only used when `AIOHTTP_NO_EXTENSIONS` is enabled (or not using a prebuilt wheel).
 
# Details&lt;/p&gt;
&lt;p&gt;## Bug 1: Bad parsing of `Content-Length` values&lt;/p&gt;
&lt;p&gt;### Description
RFC 9110 says this:
&amp;gt; `Content-Length = 1*DIGIT`&lt;/p&gt;
&lt;p&gt;AIOHTTP does not enforce this rule, presumably because of an incorrect usage of the builtin `int` constructor. Because the `int` constructor accepts `+` and `-` prefixes, and digit-separating underscores, using `int` to parse CL values leads AIOHTTP to significant misinterpretation.&lt;/p&gt;
&lt;p&gt;### Examples
```
GET / HTTP/1.1\r\n
Content-Length: -0\r\n
\r\n
X
```
```
GET / HTTP/1.1\r\n
Content-Length: +0_1\r\n
\r\n
X
```&lt;/p&gt;
&lt;p&gt;### Suggested action
Verify that a `Content-Length` value consists only of ASCII digits before parsing, as the standard requires.&lt;/p&gt;
&lt;p&gt;## Bug 2: Improper handling of NUL, CR, and LF in header values&lt;/p&gt;
&lt;p&gt;### Description
RFC 9110 says this:
&amp;gt; Field values containing CR, LF, or NUL characters are invalid and dangerous, due to the varying ways that implementations might parse and interpret those characters; a recipient of CR, LF, or NUL within a field value MUST either reject the message or replace each of those characters with SP before further processing or forwarding of that message.&lt;/p&gt;
&lt;p&gt;AIOHTTP&amp;#39;s HTTP parser does not enforce this rule, and will happily process header values containing these three forbidden characters without replacing the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: airshare&lt;/p&gt;
&lt;p&gt;# Summary
The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling.
This parser is only used when `AIOHTTP_NO_EXTENSIONS` is enabled (or not using a prebuilt wheel).
 
# Details&lt;/p&gt;
&lt;p&gt;## Bug 1: Bad parsing of `Content-Length` values&lt;/p&gt;
&lt;p&gt;### Description
RFC 9110 says this:
&amp;gt; `Content-Length = 1*DIGIT`&lt;/p&gt;
&lt;p&gt;AIOHTTP does not enforce this rule, presumably because of an incorrect usage of the builtin `int` constructor. Because the `int` constructor accepts `+` and `-` prefixes, and digit-separating underscores, using `int` to parse CL values leads AIOHTTP to significant misinterpretation.&lt;/p&gt;
&lt;p&gt;### Examples
```
GET / HTTP/1.1\r\n
Content-Length: -0\r\n
\r\n
X
```
```
GET / HTTP/1.1\r\n
Content-Length: +0_1\r\n
\r\n
X
```&lt;/p&gt;
&lt;p&gt;### Suggested action
Verify that a `Content-Length` value consists only of ASCII digits before parsing, as the standard requires.&lt;/p&gt;
&lt;p&gt;## Bug 2: Improper handling of NUL, CR, and LF in header values&lt;/p&gt;
&lt;p&gt;### Description
RFC 9110 says this:
&amp;gt; Field values containing CR, LF, or NUL characters are invalid and dangerous, due to the varying ways that implementations might parse and interpret those characters; a recipient of CR, LF, or NUL within a field value MUST either reject the message or replace each of those characters with SP before further processing or forwarding of that message.&lt;/p&gt;
&lt;p&gt;AIOHTTP&amp;#39;s HTTP parser does not enforce this rule, and will happily process header values containing these three forbidden characters without replacing the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-airshare-cve-2023-47627</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0145 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</link>
      <description>certfr-2024-avi-0145</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</guid>
    </item>
    <item>
      <title>EUVD-2026-258094</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258094</link>
      <description>EUVD-2026-258094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258094</guid>
    </item>
    <item>
      <title>fkie_cve-2023-47627</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-47627</link>
      <description>&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-47627</guid>
    </item>
    <item>
      <title>GHSA-gfw2-4jvh-wgfg — AIOHTTP has problems in HTTP parser (the python one, not llhttp)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gfw2-4jvh-wgfg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;# Summary
The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling.
This parser is only used when `AIOHTTP_NO_EXTENSIONS` is enabled (or not using a prebuilt wheel).
 
# Details&lt;/p&gt;
&lt;p&gt;## Bug 1: Bad parsing of `Content-Length` values&lt;/p&gt;
&lt;p&gt;### Description
RFC 9110 says this:
&amp;gt; `Content-Length = 1*DIGIT`&lt;/p&gt;
&lt;p&gt;AIOHTTP does not enforce this rule, presumably because of an incorrect usage of the builtin `int` constructor. Because the `int` constructor accepts `+` and `-` prefixes, and digit-separating underscores, using `int` to parse CL values leads AIOHTTP to significant misinterpretation.&lt;/p&gt;
&lt;p&gt;### Examples
```
GET / HTTP/1.1\r\n
Content-Length: -0\r\n
\r\n
X
```
```
GET / HTTP/1.1\r\n
Content-Length: +0_1\r\n
\r\n
X
```&lt;/p&gt;
&lt;p&gt;### Suggested action
Verify that a `Content-Length` value consists only of ASCII digits before parsing, as the standard requires.&lt;/p&gt;
&lt;p&gt;## Bug 2: Improper handling of NUL, CR, and LF in header values&lt;/p&gt;
&lt;p&gt;### Description
RFC 9110 says this:
&amp;gt; Field values containing CR, LF, or NUL characters are invalid and dangerous, due to the varying ways that implementations might parse and interpret those characters; a recipient of CR, LF, or NUL within a field value MUST either reject the message or replace each of those characters with SP before further processing or forwarding of that message.&lt;/p&gt;
&lt;p&gt;AIOHTTP&amp;#39;s HTTP parser does not enforce this rule, and will happily process header values containing these three forbidden characters without replacing the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;# Summary
The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling.
This parser is only used when `AIOHTTP_NO_EXTENSIONS` is enabled (or not using a prebuilt wheel).
 
# Details&lt;/p&gt;
&lt;p&gt;## Bug 1: Bad parsing of `Content-Length` values&lt;/p&gt;
&lt;p&gt;### Description
RFC 9110 says this:
&amp;gt; `Content-Length = 1*DIGIT`&lt;/p&gt;
&lt;p&gt;AIOHTTP does not enforce this rule, presumably because of an incorrect usage of the builtin `int` constructor. Because the `int` constructor accepts `+` and `-` prefixes, and digit-separating underscores, using `int` to parse CL values leads AIOHTTP to significant misinterpretation.&lt;/p&gt;
&lt;p&gt;### Examples
```
GET / HTTP/1.1\r\n
Content-Length: -0\r\n
\r\n
X
```
```
GET / HTTP/1.1\r\n
Content-Length: +0_1\r\n
\r\n
X
```&lt;/p&gt;
&lt;p&gt;### Suggested action
Verify that a `Content-Length` value consists only of ASCII digits before parsing, as the standard requires.&lt;/p&gt;
&lt;p&gt;## Bug 2: Improper handling of NUL, CR, and LF in header values&lt;/p&gt;
&lt;p&gt;### Description
RFC 9110 says this:
&amp;gt; Field values containing CR, LF, or NUL characters are invalid and dangerous, due to the varying ways that implementations might parse and interpret those characters; a recipient of CR, LF, or NUL within a field value MUST either reject the message or replace each of those characters with SP before further processing or forwarding of that message.&lt;/p&gt;
&lt;p&gt;AIOHTTP&amp;#39;s HTTP parser does not enforce this rule, and will happily process header values containing these three forbidden characters without replacing the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gfw2-4jvh-wgfg</guid>
    </item>
    <item>
      <title>gsd-2023-47627</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-47627</link>
      <description>gsd-2023-47627</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-47627</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-47627 — Request smuggling in aiohttp</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-47627</link>
      <description>msrc_CVE-2023-47627</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-47627</guid>
    </item>
    <item>
      <title>OESA-2025-1250 — python-aiohttp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1250</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python-aiohttp&lt;/p&gt;
&lt;p&gt;Async http client/server framework (asyncio).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.(CVE-2023-47627)&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method. The vulnerability occurs only if the attacker can control the HTTP method (GET, POST etc.) of the request. If the attacker can control the HTTP version of the request it will be able to modify the request (request smuggling). This issue has been patched in version 3.9.0.(CVE-2023-49082)&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option &amp;amp;apos;follow_symlinks&amp;amp;apos; can be used to determine whether to follow symbolic links outside the static root directory. When &amp;amp;apos;follow_symlinks&amp;amp;apos; is set to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python-aiohttp&lt;/p&gt;
&lt;p&gt;Async http client/server framework (asyncio).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.(CVE-2023-47627)&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method. The vulnerability occurs only if the attacker can control the HTTP method (GET, POST etc.) of the request. If the attacker can control the HTTP version of the request it will be able to modify the request (request smuggling). This issue has been patched in version 3.9.0.(CVE-2023-49082)&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option &amp;amp;apos;follow_symlinks&amp;amp;apos; can be used to determine whether to follow symbolic links outside the static root directory. When &amp;amp;apos;follow_symlinks&amp;amp;apos; is set to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1250</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13465-1 — python310-aiohttp-3.9.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13465-1</link>
      <description>&lt;p&gt;python310-aiohttp-3.9.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-aiohttp-3.9.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13465-1</guid>
    </item>
    <item>
      <title>PYSEC-2023-246</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2023-246</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2023-246</guid>
    </item>
    <item>
      <title>RHSA-2024:1057 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:1057</link>
      <description>&lt;p&gt;pygments: ReDoS in pygments python-pillow: uncontrolled resource consumption when textlength in an ImageDraw instance operates on a long text argument python-aiohttp: numerous issues in HTTP parser with header parsing aiohttp: HTTP request modification aiohttp: CRLF injection if user controls the HTTP method using aiohttp client pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex platform: Insecure websocket used when interacting with EDA server jinja2: HTML attribute injection when passing user input as keys to xmlattr filter Django: denial-of-service in ``intcomma`` template filter&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pygments: ReDoS in pygments python-pillow: uncontrolled resource consumption when textlength in an ImageDraw instance operates on a long text argument python-aiohttp: numerous issues in HTTP parser with header parsing aiohttp: HTTP request modification aiohttp: CRLF injection if user controls the HTTP method using aiohttp client pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex platform: Insecure websocket used when interacting with EDA server jinja2: HTML attribute injection when passing user input as keys to xmlattr filter Django: denial-of-service in ``intcomma`` template filter&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:1057</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-47627</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-47627</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-47627</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0522 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0522</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, Phishing-Angriffe durchzuführen oder Cross-Site Scripting (XSS)-Angriffe auszuführen. Einige dieser Schwachstellen erfordern eine Benutzerinteraktion, um sie erfolgreich auszunutzen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, Phishing-Angriffe durchzuführen oder Cross-Site Scripting (XSS)-Angriffe auszuführen. Einige dieser Schwachstellen erfordern eine Benutzerinteraktion, um sie erfolgreich auszunutzen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0522</guid>
    </item>
  </channel>
</rss>
