<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:06:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09578</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09578</link>
      <description>bdu:2026-09578</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09578</guid>
    </item>
    <item>
      <title>BREW-aider-CVE-2026-34520 — AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/secu…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-34520</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The C parser (the default for most installs) accepted null bytes and control characters in request headers.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker could send header values that are interpreted differently than expected due to the presence of control characters. For example, `request.url.origin()` may return a different value than the raw Host header, or what a reverse proxy interpreted it as., potentially resulting in some kind of security bypass.&lt;/p&gt;
&lt;p&gt;-----&lt;/p&gt;
&lt;p&gt;Patch: https://github.com/aio-libs/aiohttp/commit/9370b9714a7a56003cacd31a9b4ae16eab109ba4&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The C parser (the default for most installs) accepted null bytes and control characters in request headers.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker could send header values that are interpreted differently than expected due to the presence of control characters. For example, `request.url.origin()` may return a different value than the raw Host header, or what a reverse proxy interpreted it as., potentially resulting in some kind of security bypass.&lt;/p&gt;
&lt;p&gt;-----&lt;/p&gt;
&lt;p&gt;Patch: https://github.com/aio-libs/aiohttp/commit/9370b9714a7a56003cacd31a9b4ae16eab109ba4&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-34520</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0550 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0550</link>
      <description>certfr-2026-avi-0550</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0550</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AN24336 — Security fixes for CVE-2024-12797, CVE-2024-52303, CVE-2024-52304, CVE-2024-56201, CVE-2024-56326, CVE-2025-24023, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-an24336</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-2&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the airflow-2 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-2&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the airflow-2 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-an24336</guid>
    </item>
    <item>
      <title>EUVD-2026-280248</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280248</link>
      <description>EUVD-2026-280248</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280248</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34520</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34520</link>
      <description>&lt;p&gt;AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34520</guid>
    </item>
    <item>
      <title>GHSA-63hf-3vf5-4wqf — AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/secu…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-63hf-3vf5-4wqf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The C parser (the default for most installs) accepted null bytes and control characters in request headers.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker could send header values that are interpreted differently than expected due to the presence of control characters. For example, `request.url.origin()` may return a different value than the raw Host header, or what a reverse proxy interpreted it as., potentially resulting in some kind of security bypass.&lt;/p&gt;
&lt;p&gt;-----&lt;/p&gt;
&lt;p&gt;Patch: https://github.com/aio-libs/aiohttp/commit/9370b9714a7a56003cacd31a9b4ae16eab109ba4&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The C parser (the default for most installs) accepted null bytes and control characters in request headers.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker could send header values that are interpreted differently than expected due to the presence of control characters. For example, `request.url.origin()` may return a different value than the raw Host header, or what a reverse proxy interpreted it as., potentially resulting in some kind of security bypass.&lt;/p&gt;
&lt;p&gt;-----&lt;/p&gt;
&lt;p&gt;Patch: https://github.com/aio-libs/aiohttp/commit/9370b9714a7a56003cacd31a9b4ae16eab109ba4&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-63hf-3vf5-4wqf</guid>
    </item>
    <item>
      <title>NCSC-2026-0256 — Kwetsbaarheden verholpen in Oracle Communications</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0256</link>
      <description>NCSC-2026-0256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0256</guid>
    </item>
    <item>
      <title>OESA-2026-2192 — python-aiohttp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2192</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-aiohttp&lt;/p&gt;
&lt;p&gt;Async http client/server framework (asyncio).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Insufficient restrictions in header/trailer handling could cause uncapped memory usage.(CVE-2026-22815)&lt;/p&gt;
&lt;p&gt;An unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation.(CVE-2026-34513)&lt;/p&gt;
&lt;p&gt;An attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits.(CVE-2026-34514)&lt;/p&gt;
&lt;p&gt;A response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability.(CVE-2026-34516)&lt;/p&gt;
&lt;p&gt;For some multipart form fields, aiohttp read the entire field into memory before checking client_max_size.(CVE-2026-34517)&lt;/p&gt;
&lt;p&gt;When following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers.(CVE-2026-34518)&lt;/p&gt;
&lt;p&gt;aiohttp is vulnerable to HTTP response splitting attacks. An attacker can insert carriage return (\r) characters in the reason phrase to craft malicious responses, leading to response splitting attacks. This vulnerability affects aiohttp versions up to and including 3.13.3.(CVE-2026-34519)&lt;/p&gt;
&lt;p&gt;The llhttp parser in aiohttp accepts null bytes and control characters in response header values, which could allow attackers to perform HTTP header injection attacks and bypass security restrictions.(CVE-2026-34520)&lt;/p&gt;
&lt;p&gt;aiohttp is a Python asynchronous HTTP client/server framework. In version 3.13.3 and earlier, there is a sec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-aiohttp&lt;/p&gt;
&lt;p&gt;Async http client/server framework (asyncio).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Insufficient restrictions in header/trailer handling could cause uncapped memory usage.(CVE-2026-22815)&lt;/p&gt;
&lt;p&gt;An unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation.(CVE-2026-34513)&lt;/p&gt;
&lt;p&gt;An attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits.(CVE-2026-34514)&lt;/p&gt;
&lt;p&gt;A response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability.(CVE-2026-34516)&lt;/p&gt;
&lt;p&gt;For some multipart form fields, aiohttp read the entire field into memory before checking client_max_size.(CVE-2026-34517)&lt;/p&gt;
&lt;p&gt;When following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers.(CVE-2026-34518)&lt;/p&gt;
&lt;p&gt;aiohttp is vulnerable to HTTP response splitting attacks. An attacker can insert carriage return (\r) characters in the reason phrase to craft malicious responses, leading to response splitting attacks. This vulnerability affects aiohttp versions up to and including 3.13.3.(CVE-2026-34519)&lt;/p&gt;
&lt;p&gt;The llhttp parser in aiohttp accepts null bytes and control characters in response header values, which could allow attackers to perform HTTP header injection attacks and bypass security restrictions.(CVE-2026-34520)&lt;/p&gt;
&lt;p&gt;aiohttp is a Python asynchronous HTTP client/server framework. In version 3.13.3 and earlier, there is a sec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2192</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10545-1 — python311-aiohttp-3.13.5-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10545-1</link>
      <description>&lt;p&gt;python311-aiohttp-3.13.5-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-aiohttp-3.13.5-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10545-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2102</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2102</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aiohttp&lt;/p&gt;
&lt;p&gt;AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2102</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22173-1 — Security update for python-aiohttp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22173-1</link>
      <description>&lt;p&gt;Security update for python-aiohttp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-aiohttp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22173-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-34520</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34520</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-aiohttp, Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:20.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp, Ubuntu:Pro:24.04:LTS: python-aiohttp, Ubuntu:25.10: python-aiohttp, Ubuntu:Pro:26.04:LTS: python-aiohttp&lt;/p&gt;
&lt;p&gt;AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-aiohttp, Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:20.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp, Ubuntu:Pro:24.04:LTS: python-aiohttp, Ubuntu:25.10: python-aiohttp, Ubuntu:Pro:26.04:LTS: python-aiohttp&lt;/p&gt;
&lt;p&gt;AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34520</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2437 — Oracle Communications: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2437</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2437</guid>
    </item>
  </channel>
</rss>
