<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 01:33:10 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0236 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un déni de s…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0236</link>
      <description>certfr-2026-avi-0236</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0236</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-DR86429 — Security fix for CVE-2026-26999 applied in: forecastle 1.0.159-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-dr86429</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: forecastle&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the forecastle package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: forecastle&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the forecastle package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-dr86429</guid>
    </item>
    <item>
      <title>EUVD-2026-337432</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337432</link>
      <description>EUVD-2026-337432</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337432</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26999</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26999</link>
      <description>&lt;p&gt;Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing TLS handshake on TCP routers. When Traefik processes a TLS connection on a TCP router, the read deadline used to bound protocol sniffing is cleared before the TLS handshake is completed. When a TLS handshake read error occurs, the code attempts a second handshake with different connection parameters, silently ignoring the initial error. A remote unauthenticated client can exploit this by sending an incomplete TLS record and stopping further data transmission, causing the TLS handshake to stall indefinitely and holding connections open. By opening many such stalled connections in parallel, an attacker can exhaust file descriptors and goroutines, degrading availability of all services on the affected entrypoint. This issue has been patched in versions 2.11.38 and 3.6.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing TLS handshake on TCP routers. When Traefik processes a TLS connection on a TCP router, the read deadline used to bound protocol sniffing is cleared before the TLS handshake is completed. When a TLS handshake read error occurs, the code attempts a second handshake with different connection parameters, silently ignoring the initial error. A remote unauthenticated client can exploit this by sending an incomplete TLS record and stopping further data transmission, causing the TLS handshake to stall indefinitely and holding connections open. By opening many such stalled connections in parallel, an attacker can exhaust file descriptors and goroutines, degrading availability of all services on the affected entrypoint. This issue has been patched in versions 2.11.38 and 3.6.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26999</guid>
    </item>
    <item>
      <title>GHSA-xw98-5q62-jx94 — Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xw98-5q62-jx94</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;There is a potential vulnerability in Traefik managing TLS handshake on TCP routers.&lt;/p&gt;
&lt;p&gt;When Traefik processes a TLS connection on a TCP router, the read deadline used to bound protocol sniffing is cleared before the TLS handshake is completed. When a TLS handshake read error occurs, the code attempts a second handshake with different connection parameters, silently ignoring the initial error. A remote unauthenticated client can exploit this by sending an incomplete TLS record and stopping further data transmission, causing the TLS handshake to stall indefinitely and holding connections open.&lt;/p&gt;
&lt;p&gt;By opening many such stalled connections in parallel, an attacker can exhaust file descriptors and goroutines, degrading availability of all services on the affected entrypoint.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v2.11.38
- https://github.com/traefik/traefik/releases/tag/v3.6.9&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;No workaround available.&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If there are any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;Traefik&amp;#39;s TCP router uses a connection-level read deadline to bound protocol sniffing (peeking a TLS client hello), but then clears the deadline via conn.SetDeadline(time.Time{}) before delegating the connection to TLS forwarding.&lt;/p&gt;
&lt;p&gt;A remote unauthenticated client can send an incomplete TLS record header and stop sending data. Af…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;There is a potential vulnerability in Traefik managing TLS handshake on TCP routers.&lt;/p&gt;
&lt;p&gt;When Traefik processes a TLS connection on a TCP router, the read deadline used to bound protocol sniffing is cleared before the TLS handshake is completed. When a TLS handshake read error occurs, the code attempts a second handshake with different connection parameters, silently ignoring the initial error. A remote unauthenticated client can exploit this by sending an incomplete TLS record and stopping further data transmission, causing the TLS handshake to stall indefinitely and holding connections open.&lt;/p&gt;
&lt;p&gt;By opening many such stalled connections in parallel, an attacker can exhaust file descriptors and goroutines, degrading availability of all services on the affected entrypoint.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v2.11.38
- https://github.com/traefik/traefik/releases/tag/v3.6.9&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;No workaround available.&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If there are any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;Traefik&amp;#39;s TCP router uses a connection-level read deadline to bound protocol sniffing (peeking a TLS client hello), but then clears the deadline via conn.SetDeadline(time.Time{}) before delegating the connection to TLS forwarding.&lt;/p&gt;
&lt;p&gt;A remote unauthenticated client can send an incomplete TLS record header and stop sending data. Af…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xw98-5q62-jx94</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10314-1 — traefik2-2.11.40-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10314-1</link>
      <description>&lt;p&gt;traefik2-2.11.40-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;traefik2-2.11.40-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10314-1</guid>
    </item>
    <item>
      <title>RHSA-2026:10175 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.27.1 Release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10175</link>
      <description>&lt;p&gt;golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10175</guid>
    </item>
  </channel>
</rss>
