<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:30:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-373643</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-373643</link>
      <description>EUVD-2026-373643</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-373643</guid>
    </item>
    <item>
      <title>fkie_cve-2026-14180</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-14180</link>
      <description>&lt;p&gt;A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, &amp;#34;smuggled&amp;#34; request to be processed out of sync, potentially bypassing security controls.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, &amp;#34;smuggled&amp;#34; request to be processed out of sync, potentially bypassing security controls.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-14180</guid>
    </item>
    <item>
      <title>GHSA-x562-68w7-4xvf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x562-68w7-4xvf</link>
      <description>&lt;p&gt;A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, &amp;#34;smuggled&amp;#34; request to be processed out of sync, potentially bypassing security controls.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, &amp;#34;smuggled&amp;#34; request to be processed out of sync, potentially bypassing security controls.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x562-68w7-4xvf</guid>
    </item>
    <item>
      <title>RHSA-2026:70228 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.1.8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:70228</link>
      <description>&lt;p&gt;bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion undertow-core: Undertow: Denial of Service via WebSocket permessage-deflate processing org.wildfly.security/wildfly-elytron-asn1: Unbounded Memory Allocation in WildFly Elytron ASN.1 DERDecoder via Crafted DER Payload undertow-core: Undertow:HTTP request smuggling via oversized chunk-size bit overlap undertow-core: Undertow: Authentication Bypass via AJP ssl_cert/is_ssl Forgery jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller openjdk-orb: unauthed class loading via IIOP in EAP undertow-core: OOM via missing limits in chunked trailer in EAP&amp;#39;s Undertow jboss-remoting: jboss-remoting: integer overflow in MessageReader leads to pre-authentication denial of service wildfly-iiop-openjdk: Missing authentication on EAP&amp;#39;s IIOP NameService leads to MITM or DoS undertow: undertow-websockets: Undertow: Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method wildfly: wildfly-iiop: wildfly-jacorb: Wildfly: Pre-auth denial of service on the IIOP listener org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration wildfly-clustering-faces-mojarra: com.sun.faces:jsf-impl: org.glassfish:jakarta.faces: mojarra: Unauthenticated RCE in EAP JSF applications via EL injection in ui:include artemis-server: undertow-core: wildfly-messaging-activemq-subsystem…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion undertow-core: Undertow: Denial of Service via WebSocket permessage-deflate processing org.wildfly.security/wildfly-elytron-asn1: Unbounded Memory Allocation in WildFly Elytron ASN.1 DERDecoder via Crafted DER Payload undertow-core: Undertow:HTTP request smuggling via oversized chunk-size bit overlap undertow-core: Undertow: Authentication Bypass via AJP ssl_cert/is_ssl Forgery jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller openjdk-orb: unauthed class loading via IIOP in EAP undertow-core: OOM via missing limits in chunked trailer in EAP&amp;#39;s Undertow jboss-remoting: jboss-remoting: integer overflow in MessageReader leads to pre-authentication denial of service wildfly-iiop-openjdk: Missing authentication on EAP&amp;#39;s IIOP NameService leads to MITM or DoS undertow: undertow-websockets: Undertow: Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method wildfly: wildfly-iiop: wildfly-jacorb: Wildfly: Pre-auth denial of service on the IIOP listener org.apache.cxf/cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration wildfly-clustering-faces-mojarra: com.sun.faces:jsf-impl: org.glassfish:jakarta.faces: mojarra: Unauthenticated RCE in EAP JSF applications via EL injection in ui:include artemis-server: undertow-core: wildfly-messaging-activemq-subsystem…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:70228</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-14180</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-14180</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:Pro:20.04:LTS: undertow, Ubuntu:Pro:22.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:26.04:LTS: undertow&lt;/p&gt;
&lt;p&gt;A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, &amp;#34;smuggled&amp;#34; request to be processed out of sync, potentially bypassing security controls.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:Pro:20.04:LTS: undertow, Ubuntu:Pro:22.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:26.04:LTS: undertow&lt;/p&gt;
&lt;p&gt;A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, &amp;#34;smuggled&amp;#34; request to be processed out of sync, potentially bypassing security controls.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-14180</guid>
    </item>
  </channel>
</rss>
