<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:44:36 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-10911</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10911</link>
      <description>bdu:2025-10911</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10911</guid>
    </item>
    <item>
      <title>BREW-serveit-CVE-2025-6442 — Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling</title>
      <link>https://cve.radiocsirt.org/vuln/brew-serveit-cve-2025-6442</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: serveit&lt;/p&gt;
&lt;p&gt;Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: serveit&lt;/p&gt;
&lt;p&gt;Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-serveit-cve-2025-6442</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0760 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0760</link>
      <description>certfr-2025-avi-0760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0760</guid>
    </item>
    <item>
      <title>EUVD-2026-245878</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-245878</link>
      <description>EUVD-2026-245878</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-245878</guid>
    </item>
    <item>
      <title>fkie_cve-2025-6442</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-6442</link>
      <description>&lt;p&gt;Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-6442</guid>
    </item>
    <item>
      <title>GHSA-r995-q44h-hr64 — Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r995-q44h-hr64</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: webrick&lt;/p&gt;
&lt;p&gt;Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: webrick&lt;/p&gt;
&lt;p&gt;Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r995-q44h-hr64</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-6442 — Ruby WEBrick read_header HTTP Request Smuggling Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-6442</link>
      <description>msrc_CVE-2025-6442</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-6442</guid>
    </item>
    <item>
      <title>OESA-2025-1930 — ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1930</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Webrick is an open source HTTP server toolkit for The Ruby Programming Language.
 Webrick has an environmental problem vulnerability, which originates from the inconsistent parsing of HTTP header terminators by the read_headers method, which may lead to an HTTP request entrainment attack.(CVE-2025-6442)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Webrick is an open source HTTP server toolkit for The Ruby Programming Language.
 Webrick has an environmental problem vulnerability, which originates from the inconsistent parsing of HTTP header terminators by the read_headers method, which may lead to an HTTP request entrainment attack.(CVE-2025-6442)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1930</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02739-1 — Security update for ruby2.5</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02739-1</link>
      <description>&lt;p&gt;Security update for ruby2.5&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ruby2.5&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02739-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-6442</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6442</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:16.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby-webrick, Ubuntu:24.04:LTS: ruby-webrick, Ubuntu:25.10: ruby-webrick and 1 more&lt;/p&gt;
&lt;p&gt;Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:16.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby-webrick, Ubuntu:24.04:LTS: ruby-webrick, Ubuntu:25.10: ruby-webrick and 1 more&lt;/p&gt;
&lt;p&gt;Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6442</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2475 — Apple macOS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2475</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apple macOS ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Dateien zu manipulieren, und um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apple macOS ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Dateien zu manipulieren, und um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2475</guid>
    </item>
  </channel>
</rss>
