<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:41:29 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-00996</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00996</link>
      <description>bdu:2024-00996</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00996</guid>
    </item>
    <item>
      <title>BREW-airshare-CVE-2024-23829 — aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators</title>
      <link>https://cve.radiocsirt.org/vuln/brew-airshare-cve-2024-23829</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: airshare&lt;/p&gt;
&lt;p&gt;### Summary
Security-sensitive parts of the *Python HTTP parser* retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.&lt;/p&gt;
&lt;p&gt;### Details
These problems are rooted in pattern matching protocol elements, previously improved by PR #3235 and GHSA-gfw2-4jvh-wgfg:&lt;/p&gt;
&lt;p&gt;1. The expression `HTTP/(\d).(\d)` lacked another backslash to clarify that the separator should be a literal dot, not just *any* Unicode code point (result: `HTTP/(\d)\.(\d)`).&lt;/p&gt;
&lt;p&gt;2. The HTTP version was permitting Unicode digits, where only ASCII digits are standards-compliant.&lt;/p&gt;
&lt;p&gt;3. Distinct regular expressions for validating HTTP Method and Header field names were used - though both should (at least) apply the common restrictions of rfc9110 `token`.&lt;/p&gt;
&lt;p&gt;### PoC
`GET / HTTP/1ö1`
`GET / HTTP/1.𝟙`
`GET/: HTTP/1.1`
`Content-Encoding?: chunked`&lt;/p&gt;
&lt;p&gt;### Impact
Primarily concerns running an aiohttp server without llhttp:
 1. **behind a proxy**: Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling.
 2. **directly accessible** or exposed behind proxies relaying malformed input: the unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities.&lt;/p&gt;
&lt;p&gt;-----…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: airshare&lt;/p&gt;
&lt;p&gt;### Summary
Security-sensitive parts of the *Python HTTP parser* retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.&lt;/p&gt;
&lt;p&gt;### Details
These problems are rooted in pattern matching protocol elements, previously improved by PR #3235 and GHSA-gfw2-4jvh-wgfg:&lt;/p&gt;
&lt;p&gt;1. The expression `HTTP/(\d).(\d)` lacked another backslash to clarify that the separator should be a literal dot, not just *any* Unicode code point (result: `HTTP/(\d)\.(\d)`).&lt;/p&gt;
&lt;p&gt;2. The HTTP version was permitting Unicode digits, where only ASCII digits are standards-compliant.&lt;/p&gt;
&lt;p&gt;3. Distinct regular expressions for validating HTTP Method and Header field names were used - though both should (at least) apply the common restrictions of rfc9110 `token`.&lt;/p&gt;
&lt;p&gt;### PoC
`GET / HTTP/1ö1`
`GET / HTTP/1.𝟙`
`GET/: HTTP/1.1`
`Content-Encoding?: chunked`&lt;/p&gt;
&lt;p&gt;### Impact
Primarily concerns running an aiohttp server without llhttp:
 1. **behind a proxy**: Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling.
 2. **directly accessible** or exposed behind proxies relaying malformed input: the unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities.&lt;/p&gt;
&lt;p&gt;-----…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-airshare-cve-2024-23829</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0199 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199</link>
      <description>certfr-2024-avi-0199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199</guid>
    </item>
    <item>
      <title>EUVD-2026-258104</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258104</link>
      <description>EUVD-2026-258104</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258104</guid>
    </item>
    <item>
      <title>fkie_cve-2024-23829</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23829</link>
      <description>&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.  Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.  Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-23829</guid>
    </item>
    <item>
      <title>GHSA-8qpw-xqxj-h4r2 — aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8qpw-xqxj-h4r2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;### Summary
Security-sensitive parts of the *Python HTTP parser* retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.&lt;/p&gt;
&lt;p&gt;### Details
These problems are rooted in pattern matching protocol elements, previously improved by PR #3235 and GHSA-gfw2-4jvh-wgfg:&lt;/p&gt;
&lt;p&gt;1. The expression `HTTP/(\d).(\d)` lacked another backslash to clarify that the separator should be a literal dot, not just *any* Unicode code point (result: `HTTP/(\d)\.(\d)`).&lt;/p&gt;
&lt;p&gt;2. The HTTP version was permitting Unicode digits, where only ASCII digits are standards-compliant.&lt;/p&gt;
&lt;p&gt;3. Distinct regular expressions for validating HTTP Method and Header field names were used - though both should (at least) apply the common restrictions of rfc9110 `token`.&lt;/p&gt;
&lt;p&gt;### PoC
`GET / HTTP/1ö1`
`GET / HTTP/1.𝟙`
`GET/: HTTP/1.1`
`Content-Encoding?: chunked`&lt;/p&gt;
&lt;p&gt;### Impact
Primarily concerns running an aiohttp server without llhttp:
 1. **behind a proxy**: Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling.
 2. **directly accessible** or exposed behind proxies relaying malformed input: the unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities.&lt;/p&gt;
&lt;p&gt;-----…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;### Summary
Security-sensitive parts of the *Python HTTP parser* retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.&lt;/p&gt;
&lt;p&gt;### Details
These problems are rooted in pattern matching protocol elements, previously improved by PR #3235 and GHSA-gfw2-4jvh-wgfg:&lt;/p&gt;
&lt;p&gt;1. The expression `HTTP/(\d).(\d)` lacked another backslash to clarify that the separator should be a literal dot, not just *any* Unicode code point (result: `HTTP/(\d)\.(\d)`).&lt;/p&gt;
&lt;p&gt;2. The HTTP version was permitting Unicode digits, where only ASCII digits are standards-compliant.&lt;/p&gt;
&lt;p&gt;3. Distinct regular expressions for validating HTTP Method and Header field names were used - though both should (at least) apply the common restrictions of rfc9110 `token`.&lt;/p&gt;
&lt;p&gt;### PoC
`GET / HTTP/1ö1`
`GET / HTTP/1.𝟙`
`GET/: HTTP/1.1`
`Content-Encoding?: chunked`&lt;/p&gt;
&lt;p&gt;### Impact
Primarily concerns running an aiohttp server without llhttp:
 1. **behind a proxy**: Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling.
 2. **directly accessible** or exposed behind proxies relaying malformed input: the unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities.&lt;/p&gt;
&lt;p&gt;-----…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8qpw-xqxj-h4r2</guid>
    </item>
    <item>
      <title>gsd-2024-23829</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-23829</link>
      <description>gsd-2024-23829</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-23829</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-23829 — aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-23829</link>
      <description>msrc_CVE-2024-23829</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-23829</guid>
    </item>
    <item>
      <title>OESA-2025-1250 — python-aiohttp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1250</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python-aiohttp&lt;/p&gt;
&lt;p&gt;Async http client/server framework (asyncio).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.(CVE-2023-47627)&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method. The vulnerability occurs only if the attacker can control the HTTP method (GET, POST etc.) of the request. If the attacker can control the HTTP version of the request it will be able to modify the request (request smuggling). This issue has been patched in version 3.9.0.(CVE-2023-49082)&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option &amp;amp;apos;follow_symlinks&amp;amp;apos; can be used to determine whether to follow symbolic links outside the static root directory. When &amp;amp;apos;follow_symlinks&amp;amp;apos; is set to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python-aiohttp&lt;/p&gt;
&lt;p&gt;Async http client/server framework (asyncio).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.(CVE-2023-47627)&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method. The vulnerability occurs only if the attacker can control the HTTP method (GET, POST etc.) of the request. If the attacker can control the HTTP version of the request it will be able to modify the request (request smuggling). This issue has been patched in version 3.9.0.(CVE-2023-49082)&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option &amp;amp;apos;follow_symlinks&amp;amp;apos; can be used to determine whether to follow symbolic links outside the static root directory. When &amp;amp;apos;follow_symlinks&amp;amp;apos; is set to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1250</guid>
    </item>
    <item>
      <title>PYSEC-2024-26</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2024-26</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.  Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.  Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2024-26</guid>
    </item>
    <item>
      <title>RHSA-2024:1536 — Red Hat Security Advisory: Satellite 6.14.3 Async Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:1536</link>
      <description>&lt;p&gt;Hub: insecure galaxy-importer tarfile extraction python-django: Denial-of-service possibility in django.utils.text.Truncator python-aiohttp: numerous issues in HTTP parser with header parsing aiohttp: HTTP request modification jinja2: HTML attribute injection when passing user input as keys to xmlattr filter aiohttp: follow_symlinks directory traversal vulnerability python-aiohttp: http request smuggling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hub: insecure galaxy-importer tarfile extraction python-django: Denial-of-service possibility in django.utils.text.Truncator python-aiohttp: numerous issues in HTTP parser with header parsing aiohttp: HTTP request modification jinja2: HTML attribute injection when passing user input as keys to xmlattr filter aiohttp: follow_symlinks directory traversal vulnerability python-aiohttp: http request smuggling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:1536</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-23829</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23829</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp, Ubuntu:Pro:24.04:LTS: python-aiohttp&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.  Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp, Ubuntu:Pro:24.04:LTS: python-aiohttp&lt;/p&gt;
&lt;p&gt;aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.  Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23829</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0949 — Red Hat Satellite: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0949</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, HTTP-Request-Smuggling-Angriffe durchzuführen oder Phishing- und Cross-Site-Scripting (XSS)-Angriffe auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, HTTP-Request-Smuggling-Angriffe durchzuführen oder Phishing- und Cross-Site-Scripting (XSS)-Angriffe auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0949</guid>
    </item>
  </channel>
</rss>
