<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:01:43 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AG15773 — Security fixes in apache-hive 4.2.0-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ag15773</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;Package apache-hive version 4.2.0-r4 fixes 2 vulnerabilities: CVE-2026-45205, CVE-2026-45300&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-hive&lt;/p&gt;
&lt;p&gt;Package apache-hive version 4.2.0-r4 fixes 2 vulnerabilities: CVE-2026-45205, CVE-2026-45300&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ag15773</guid>
    </item>
    <item>
      <title>EUVD-2026-325580</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-325580</link>
      <description>EUVD-2026-325580</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-325580</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45300</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45300</link>
      <description>&lt;p&gt;The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45300</guid>
    </item>
    <item>
      <title>GHSA-fmxf-pm6p-7xgm — async-http-client: Cookie header not stripped on cross-origin redirect</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fmxf-pm6p-7xgm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.asynchttpclient:async-http-client&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;async-http-client leaks `Cookie` headers to cross-origin redirect targets. When following a redirect across a security boundary (different origin, or HTTPS→HTTP downgrade), the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip `Cookie`, so session cookies and other sensitive cookie values are forwarded to the redirect target — which may be attacker-controlled.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability is in `client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java`.&lt;/p&gt;
&lt;p&gt;The caller computes `stripAuth` on each redirect:&lt;/p&gt;
&lt;p&gt;```java
boolean sameBase    = request.getUri().isSameBase(newUri);
boolean stripAuth   = !sameBase || schemeDowngrade || stripAuthorizationOnRedirect;
// ...
requestBuilder.setHeaders(propagatedHeaders(request, realm, keepBody, stripAuth));
```&lt;/p&gt;
&lt;p&gt;`stripAuth` is `true` whenever the redirect crosses an origin, downgrades the scheme, or the caller opted in via `AsyncHttpClientConfig#isStripAuthorizationOnRedirect()`.&lt;/p&gt;
&lt;p&gt;In the vulnerable version, `propagatedHeaders()` only removes `Authorization` and `Proxy-Authorization` in that branch — `Cookie` is left untouched:&lt;/p&gt;
&lt;p&gt;```java
private static HttpHeaders propagatedHeaders(Request request, Realm realm, boolean keepBody, boolean stripAuthorization) {
    HttpHeaders headers = request.getHeaders()
            .remove(HOST)
            .remove(CONTENT_LENGTH);&lt;/p&gt;
&lt;p&gt;if (!keepBody) {
        headers.remo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.asynchttpclient:async-http-client&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;async-http-client leaks `Cookie` headers to cross-origin redirect targets. When following a redirect across a security boundary (different origin, or HTTPS→HTTP downgrade), the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip `Cookie`, so session cookies and other sensitive cookie values are forwarded to the redirect target — which may be attacker-controlled.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability is in `client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java`.&lt;/p&gt;
&lt;p&gt;The caller computes `stripAuth` on each redirect:&lt;/p&gt;
&lt;p&gt;```java
boolean sameBase    = request.getUri().isSameBase(newUri);
boolean stripAuth   = !sameBase || schemeDowngrade || stripAuthorizationOnRedirect;
// ...
requestBuilder.setHeaders(propagatedHeaders(request, realm, keepBody, stripAuth));
```&lt;/p&gt;
&lt;p&gt;`stripAuth` is `true` whenever the redirect crosses an origin, downgrades the scheme, or the caller opted in via `AsyncHttpClientConfig#isStripAuthorizationOnRedirect()`.&lt;/p&gt;
&lt;p&gt;In the vulnerable version, `propagatedHeaders()` only removes `Authorization` and `Proxy-Authorization` in that branch — `Cookie` is left untouched:&lt;/p&gt;
&lt;p&gt;```java
private static HttpHeaders propagatedHeaders(Request request, Realm realm, boolean keepBody, boolean stripAuthorization) {
    HttpHeaders headers = request.getHeaders()
            .remove(HOST)
            .remove(CONTENT_LENGTH);&lt;/p&gt;
&lt;p&gt;if (!keepBody) {
        headers.remo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fmxf-pm6p-7xgm</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-45300</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45300</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: async-http-client, Ubuntu:16.04:LTS: async-http-client, Ubuntu:18.04:LTS: async-http-client, Ubuntu:Pro:20.04:LTS: async-http-client, Ubuntu:22.04:LTS: async-http-client, Ubuntu:24.04:LTS: async-http-client, Ubuntu:25.10: async-http-client, Ubuntu:26.04:LTS: async-http-client&lt;/p&gt;
&lt;p&gt;The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: async-http-client, Ubuntu:16.04:LTS: async-http-client, Ubuntu:18.04:LTS: async-http-client, Ubuntu:Pro:20.04:LTS: async-http-client, Ubuntu:22.04:LTS: async-http-client, Ubuntu:24.04:LTS: async-http-client, Ubuntu:25.10: async-http-client, Ubuntu:26.04:LTS: async-http-client&lt;/p&gt;
&lt;p&gt;The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45300</guid>
    </item>
  </channel>
</rss>
