<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:01:04 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:10987 — Moderate: pcs security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:10987</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: pcs, AlmaLinux:8: pcs-snmp&lt;/p&gt;
&lt;p&gt;The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sinatra: Open Redirect Vulnerability in Sinatra via X-Forwarded-Host Header (CVE-2024-21510)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: pcs, AlmaLinux:8: pcs-snmp&lt;/p&gt;
&lt;p&gt;The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sinatra: Open Redirect Vulnerability in Sinatra via X-Forwarded-Host Header (CVE-2024-21510)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:10987</guid>
    </item>
    <item>
      <title>bdu:2025-03808</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-03808</link>
      <description>bdu:2025-03808</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-03808</guid>
    </item>
    <item>
      <title>BREW-mailcatcher-CVE-2024-21510 — Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision</title>
      <link>https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2024-21510</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mailcatcher&lt;/p&gt;
&lt;p&gt;Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mailcatcher&lt;/p&gt;
&lt;p&gt;Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2024-21510</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0967 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</link>
      <description>certfr-2025-avi-0967</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</guid>
    </item>
    <item>
      <title>EUVD-2026-202275</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-202275</link>
      <description>EUVD-2026-202275</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-202275</guid>
    </item>
    <item>
      <title>fkie_cve-2024-21510</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-21510</link>
      <description>&lt;p&gt;Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-21510</guid>
    </item>
    <item>
      <title>GHSA-hxx2-7vcw-mqr3 — Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hxx2-7vcw-mqr3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: sinatra&lt;/p&gt;
&lt;p&gt;Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: sinatra&lt;/p&gt;
&lt;p&gt;Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hxx2-7vcw-mqr3</guid>
    </item>
    <item>
      <title>gsd-2024-21510</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-21510</link>
      <description>gsd-2024-21510</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-21510</guid>
    </item>
    <item>
      <title>RHSA-2024:10987 — Red Hat Security Advisory: pcs security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:10987</link>
      <description>&lt;p&gt;sinatra: Open Redirect Vulnerability in Sinatra via X-Forwarded-Host Header&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sinatra: Open Redirect Vulnerability in Sinatra via X-Forwarded-Host Header&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:10987</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-21510</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21510</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby-sinatra, Ubuntu:Pro:18.04:LTS: ruby-sinatra, Ubuntu:Pro:20.04:LTS: ruby-sinatra, Ubuntu:22.04:LTS: ruby-sinatra, Ubuntu:24.04:LTS: ruby-sinatra&lt;/p&gt;
&lt;p&gt;Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby-sinatra, Ubuntu:Pro:18.04:LTS: ruby-sinatra, Ubuntu:Pro:20.04:LTS: ruby-sinatra, Ubuntu:22.04:LTS: ruby-sinatra, Ubuntu:24.04:LTS: ruby-sinatra&lt;/p&gt;
&lt;p&gt;Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21510</guid>
    </item>
  </channel>
</rss>
