<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:00:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-351613</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351613</link>
      <description>EUVD-2026-351613</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351613</guid>
    </item>
    <item>
      <title>fkie_cve-2026-12382</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-12382</link>
      <description>&lt;p&gt;A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-12382</guid>
    </item>
    <item>
      <title>GHSA-45w6-c976-v24q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-45w6-c976-v24q</link>
      <description>&lt;p&gt;A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-45w6-c976-v24q</guid>
    </item>
    <item>
      <title>RHSA-2026:13508 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13508</link>
      <description>&lt;p&gt;Django: Django: Denial of Service via crafted request with duplicate headers python-markdown: denial of service via malformed HTML-like sequences aap-controller: aap-gateway: Account hijacking and unauthorized access via unverified email linking aap-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID net/url: Incorrect parsing of IPv6 host literals in net/url minimatch: minimatch: Denial of Service via specially crafted glob patterns pyOpenSSL: DTLS cookie callback buffer overflow rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Django: Django: Denial of Service via crafted request with duplicate headers python-markdown: denial of service via malformed HTML-like sequences aap-controller: aap-gateway: Account hijacking and unauthorized access via unverified email linking aap-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID net/url: Incorrect parsing of IPv6 host literals in net/url minimatch: minimatch: Denial of Service via specially crafted glob patterns pyOpenSSL: DTLS cookie callback buffer overflow rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13508</guid>
    </item>
  </channel>
</rss>
