<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 04:24:13 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0617 — De multiples vulnérabilités ont été découvertes dans Symfony. Certaines d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0617</link>
      <description>certfr-2026-avi-0617</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0617</guid>
    </item>
    <item>
      <title>EUVD-2026-338253</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338253</link>
      <description>EUVD-2026-338253</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338253</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45070</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45070</link>
      <description>&lt;p&gt;Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45070</guid>
    </item>
    <item>
      <title>GHSA-vqc8-7275-q272 — Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vqc8-7275-q272</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: symfony/mime, Packagist: symfony/symfony&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;`Symfony\Component\Mime\Header\ParameterizedHeader` (and the related parameter handling reachable from `Symfony\Component\Mime\Header\Headers`) is responsible for serializing structured headers such as `Content-Type` and `Content-Disposition`, which carry `key=value` parameters (e.g. `Content-Disposition: attachment; filename=&amp;#34;x&amp;#34;`).&lt;/p&gt;
&lt;p&gt;RFC 2045 / RFC 5322 require parameter *names* to be `tokens`: a restricted ASCII subset that excludes whitespace, CR/LF, and the `tspecials` set. Symfony&amp;#39;s parameter handling validates and properly encodes parameter *values*, but does not validate parameter *names*: the supplied name is emitted verbatim into the serialized header.&lt;/p&gt;
&lt;p&gt;A caller that derives a parameter name from untrusted input, e.g. an application that lets a user influence a `Content-Disposition` parameter name, can include `\r\n` or other non-token bytes inside the name, terminating the current header and injecting additional headers in the rendered message. This is the classic CRLF / header-injection primitive applied to the parameter-name slot.&lt;/p&gt;
&lt;p&gt;### Resolution&lt;/p&gt;
&lt;p&gt;`ParameterizedHeader` now rejects parameter names that contain bytes outside the RFC `token` character class.&lt;/p&gt;
&lt;p&gt;The patch for this issue is available [here](https://github.com/symfony/symfony/commit/e62ea217f8b4ca8ae922ad0f949e0c4dc1f9b613) for branch 5.4.&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Symfony would like to thank Fabian Fleischer for reporting the issue and Alexandre Daubois for fixing it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: symfony/mime, Packagist: symfony/symfony&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;`Symfony\Component\Mime\Header\ParameterizedHeader` (and the related parameter handling reachable from `Symfony\Component\Mime\Header\Headers`) is responsible for serializing structured headers such as `Content-Type` and `Content-Disposition`, which carry `key=value` parameters (e.g. `Content-Disposition: attachment; filename=&amp;#34;x&amp;#34;`).&lt;/p&gt;
&lt;p&gt;RFC 2045 / RFC 5322 require parameter *names* to be `tokens`: a restricted ASCII subset that excludes whitespace, CR/LF, and the `tspecials` set. Symfony&amp;#39;s parameter handling validates and properly encodes parameter *values*, but does not validate parameter *names*: the supplied name is emitted verbatim into the serialized header.&lt;/p&gt;
&lt;p&gt;A caller that derives a parameter name from untrusted input, e.g. an application that lets a user influence a `Content-Disposition` parameter name, can include `\r\n` or other non-token bytes inside the name, terminating the current header and injecting additional headers in the rendered message. This is the classic CRLF / header-injection primitive applied to the parameter-name slot.&lt;/p&gt;
&lt;p&gt;### Resolution&lt;/p&gt;
&lt;p&gt;`ParameterizedHeader` now rejects parameter names that contain bytes outside the RFC `token` character class.&lt;/p&gt;
&lt;p&gt;The patch for this issue is available [here](https://github.com/symfony/symfony/commit/e62ea217f8b4ca8ae922ad0f949e0c4dc1f9b613) for branch 5.4.&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Symfony would like to thank Fabian Fleischer for reporting the issue and Alexandre Daubois for fixing it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vqc8-7275-q272</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-45070</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45070</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: symfony, Ubuntu:Pro:18.04:LTS: symfony, Ubuntu:Pro:20.04:LTS: symfony, Ubuntu:Pro:22.04:LTS: symfony, Ubuntu:Pro:24.04:LTS: symfony, Ubuntu:25.10: symfony, Ubuntu:26.04:LTS: symfony&lt;/p&gt;
&lt;p&gt;Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: symfony, Ubuntu:Pro:18.04:LTS: symfony, Ubuntu:Pro:20.04:LTS: symfony, Ubuntu:Pro:22.04:LTS: symfony, Ubuntu:Pro:24.04:LTS: symfony, Ubuntu:25.10: symfony, Ubuntu:26.04:LTS: symfony&lt;/p&gt;
&lt;p&gt;Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45070</guid>
    </item>
  </channel>
</rss>
