<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:26:40 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0823 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contourne…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0823</link>
      <description>certfr-2026-avi-0823</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0823</guid>
    </item>
    <item>
      <title>EUVD-2026-334055</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-334055</link>
      <description>EUVD-2026-334055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-334055</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54763</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54763</link>
      <description>&lt;p&gt;Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik&amp;#39;s BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik&amp;#39;s own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik&amp;#39;s stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik intended to set, spoofing identity or authorization context. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik&amp;#39;s BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik&amp;#39;s own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik&amp;#39;s stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik intended to set, spoofing identity or authorization context. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54763</guid>
    </item>
    <item>
      <title>GHSA-x677-9fxg-v5c5 — Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoof…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x677-9fxg-v5c5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;There is a high severity vulnerability in Traefik&amp;#39;s BasicAuth, DigestAuth, and ForwardAuth
middlewares. The fix for CVE-2026-33433 stripped canonical-cased spoofed identity headers
(e.g. `X-Auth-User`) before writing Traefik&amp;#39;s own value, but did not account for
underscore-variant header names (e.g. `X_Auth_User`), which many backends normalize
identically to the dashed form. An attacker able to reach a protected route could inject
an underscore-variant header that survives Traefik&amp;#39;s stripping and reaches the backend
alongside — or, on the unauthenticated ForwardAuth `authResponseHeaders` path, instead of
— the value Traefik intended to set, spoofing identity or authorization context. This is
fixed by setting the new `allowHeadersWithUnderscores: false` entry point option, which
strips all headers with underscores in their names before routing.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v2.11.51
- https://github.com/traefik/traefik/releases/tag/v3.6.22
- https://github.com/traefik/traefik/releases/tag/v3.7.6&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;# Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: `headerField` underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The fix for CVE-2026-33433 (GHSA-qr99-7898-vr7c, &amp;#34;BasicAuth/DigestAut…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;There is a high severity vulnerability in Traefik&amp;#39;s BasicAuth, DigestAuth, and ForwardAuth
middlewares. The fix for CVE-2026-33433 stripped canonical-cased spoofed identity headers
(e.g. `X-Auth-User`) before writing Traefik&amp;#39;s own value, but did not account for
underscore-variant header names (e.g. `X_Auth_User`), which many backends normalize
identically to the dashed form. An attacker able to reach a protected route could inject
an underscore-variant header that survives Traefik&amp;#39;s stripping and reaches the backend
alongside — or, on the unauthenticated ForwardAuth `authResponseHeaders` path, instead of
— the value Traefik intended to set, spoofing identity or authorization context. This is
fixed by setting the new `allowHeadersWithUnderscores: false` entry point option, which
strips all headers with underscores in their names before routing.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v2.11.51
- https://github.com/traefik/traefik/releases/tag/v3.6.22
- https://github.com/traefik/traefik/releases/tag/v3.7.6&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;# Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: `headerField` underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The fix for CVE-2026-33433 (GHSA-qr99-7898-vr7c, &amp;#34;BasicAuth/DigestAut…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x677-9fxg-v5c5</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11243-1 — traefik2-2.11.52-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11243-1</link>
      <description>&lt;p&gt;traefik2-2.11.52-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;traefik2-2.11.52-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11243-1</guid>
    </item>
    <item>
      <title>RHSA-2026:62260 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.30.0 Release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:62260</link>
      <description>&lt;p&gt;netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability curl: curl: Insecure connection establishment due to TLS configuration mismatch shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators curl: curl: Man-in-the-middle attack via SSH host key bypass org.eclipse.parsson/parsson: Eclipse Parsson: Denial of Service via uncontrolled resource consumption in JSON parsing jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections form-data: form-data: Form field override via CRLF injection undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object net/mail: golang: Go net/mail: Denial of Service via crafted email inputs golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check golang.org/x/cryp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability curl: curl: Insecure connection establishment due to TLS configuration mismatch shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators curl: curl: Man-in-the-middle attack via SSH host key bypass org.eclipse.parsson/parsson: Eclipse Parsson: Denial of Service via uncontrolled resource consumption in JSON parsing jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections form-data: form-data: Form field override via CRLF injection undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object net/mail: golang: Go net/mail: Denial of Service via crafted email inputs golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check golang.org/x/cryp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:62260</guid>
    </item>
  </channel>
</rss>
