<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:01:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-06308</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06308</link>
      <description>bdu:2024-06308</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06308</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0512 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0512</link>
      <description>certfr-2025-avi-0512</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0512</guid>
    </item>
    <item>
      <title>EUVD-2026-255086</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255086</link>
      <description>EUVD-2026-255086</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255086</guid>
    </item>
    <item>
      <title>fkie_cve-2024-6827</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-6827</link>
      <description>&lt;p&gt;Gunicorn version 21.2.0 does not properly validate the value of the &amp;#39;Transfer-Encoding&amp;#39; header as specified in the RFC standards, which leads to the default fallback method of &amp;#39;Content-Length,&amp;#39; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gunicorn version 21.2.0 does not properly validate the value of the &amp;#39;Transfer-Encoding&amp;#39; header as specified in the RFC standards, which leads to the default fallback method of &amp;#39;Content-Length,&amp;#39; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-6827</guid>
    </item>
    <item>
      <title>GHSA-hc5x-x2vx-497g — Gunicorn HTTP Request/Response Smuggling vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hc5x-x2vx-497g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gunicorn&lt;/p&gt;
&lt;p&gt;Gunicorn version 21.2.0 does not properly validate the value of the &amp;#39;Transfer-Encoding&amp;#39; header as specified in the RFC standards, which leads to the default fallback method of &amp;#39;Content-Length,&amp;#39; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gunicorn&lt;/p&gt;
&lt;p&gt;Gunicorn version 21.2.0 does not properly validate the value of the &amp;#39;Transfer-Encoding&amp;#39; header as specified in the RFC standards, which leads to the default fallback method of &amp;#39;Content-Length,&amp;#39; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hc5x-x2vx-497g</guid>
    </item>
    <item>
      <title>OESA-2026-3657 — python-gunicorn security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3657</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: python-gunicorn&lt;/p&gt;
&lt;p&gt;Gunicorn(Green Unicorn) is a Python WSGI HTTP Server for UNIX. It&amp;amp;amp;apos;s a pre-fork worker model ported from Ruby&amp;amp;amp;apos;s Unicorn_ project. The Gunicorn server is broadly compatible with various web frameworks, simply implemented, light on server resource usage, and fairly speedy.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Gunicorn version 21.2.0 does not properly validate the value of the &amp;amp;apos;Transfer-Encoding&amp;amp;apos; header as specified in the RFC standards, which leads to the default fallback method of &amp;amp;apos;Content-Length,&amp;amp;apos; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.(CVE-2024-6827)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: python-gunicorn&lt;/p&gt;
&lt;p&gt;Gunicorn(Green Unicorn) is a Python WSGI HTTP Server for UNIX. It&amp;amp;amp;apos;s a pre-fork worker model ported from Ruby&amp;amp;amp;apos;s Unicorn_ project. The Gunicorn server is broadly compatible with various web frameworks, simply implemented, light on server resource usage, and fairly speedy.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Gunicorn version 21.2.0 does not properly validate the value of the &amp;amp;apos;Transfer-Encoding&amp;amp;apos; header as specified in the RFC standards, which leads to the default fallback method of &amp;amp;apos;Content-Length,&amp;amp;apos; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.(CVE-2024-6827)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3657</guid>
    </item>
    <item>
      <title>PYSEC-2026-1433 — Gunicorn HTTP Request/Response Smuggling vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1433</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gunicorn&lt;/p&gt;
&lt;p&gt;Gunicorn version 21.2.0 does not properly validate the value of the &amp;#39;Transfer-Encoding&amp;#39; header as specified in the RFC standards, which leads to the default fallback method of &amp;#39;Content-Length,&amp;#39; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gunicorn&lt;/p&gt;
&lt;p&gt;Gunicorn version 21.2.0 does not properly validate the value of the &amp;#39;Transfer-Encoding&amp;#39; header as specified in the RFC standards, which leads to the default fallback method of &amp;#39;Content-Length,&amp;#39; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1433</guid>
    </item>
    <item>
      <title>RHBA-2025:3651 — Red Hat Bug Fix Advisory: Red Hat Quay v3.13.5 bug fix release</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:3651</link>
      <description>&lt;p&gt;gunicorn: HTTP Request Smuggling in benoitc/gunicorn golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh jinja2: Jinja sandbox breakout through attr filter selecting format method&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gunicorn: HTTP Request Smuggling in benoitc/gunicorn golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh jinja2: Jinja sandbox breakout through attr filter selecting format method&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:3651</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-6827</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6827</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gunicorn, Ubuntu:16.04:LTS: gunicorn, Ubuntu:18.04:LTS: gunicorn, Ubuntu:20.04:LTS: gunicorn, Ubuntu:22.04:LTS: gunicorn, Ubuntu:24.04:LTS: gunicorn, Ubuntu:25.10: gunicorn, Ubuntu:26.04:LTS: gunicorn&lt;/p&gt;
&lt;p&gt;Gunicorn version 21.2.0 does not properly validate the value of the &amp;#39;Transfer-Encoding&amp;#39; header as specified in the RFC standards, which leads to the default fallback method of &amp;#39;Content-Length,&amp;#39; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gunicorn, Ubuntu:16.04:LTS: gunicorn, Ubuntu:18.04:LTS: gunicorn, Ubuntu:20.04:LTS: gunicorn, Ubuntu:22.04:LTS: gunicorn, Ubuntu:24.04:LTS: gunicorn, Ubuntu:25.10: gunicorn, Ubuntu:26.04:LTS: gunicorn&lt;/p&gt;
&lt;p&gt;Gunicorn version 21.2.0 does not properly validate the value of the &amp;#39;Transfer-Encoding&amp;#39; header as specified in the RFC standards, which leads to the default fallback method of &amp;#39;Content-Length,&amp;#39; making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6827</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0998 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0998</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren, vertrauliche Informationen preiszugeben und einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren, vertrauliche Informationen preiszugeben und einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0998</guid>
    </item>
  </channel>
</rss>
