<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:39:42 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12654</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12654</link>
      <description>bdu:2026-12654</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12654</guid>
    </item>
    <item>
      <title>EUVD-2026-358702</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358702</link>
      <description>EUVD-2026-358702</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358702</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54770</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54770</link>
      <description>&lt;p&gt;WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled value such as a space followed by a protocol-relative or absolute URL can therefore bypass SCHEME_RE and startswith(&amp;#34;//&amp;#34;) checks and be normalized to an off-host redirect. Request.relative_url() and webob.exc._HTTPMove subclasses, including HTTPFound, are also affected because they use the same unsafe URL joining behavior or bypass the earlier normalization path. An unauthenticated attacker who can influence an application&amp;#39;s redirect target can send users to an attacker-controlled host for phishing or OAuth and SSO token theft, but exploitation requires the user to follow the redirect. This issue is fixed in version 1.8.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled value such as a space followed by a protocol-relative or absolute URL can therefore bypass SCHEME_RE and startswith(&amp;#34;//&amp;#34;) checks and be normalized to an off-host redirect. Request.relative_url() and webob.exc._HTTPMove subclasses, including HTTPFound, are also affected because they use the same unsafe URL joining behavior or bypass the earlier normalization path. An unauthenticated attacker who can influence an application&amp;#39;s redirect target can send users to an attacker-controlled host for phishing or OAuth and SSO token theft, but exploitation requires the user to follow the redirect. This issue is fixed in version 1.8.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54770</guid>
    </item>
    <item>
      <title>GHSA-6hx8-3wjj-gr8g — WebOb: Open redirect in Location header normalization via leading C0 control / space characters</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6hx8-3wjj-gr8g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: webob&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;This is a third follow-up to **CVE-2024-42353 / GHSA-mg3v-6m49-jhp3**
and **CVE-2026-44889 / GHSA-fh3h-vg37-cc95**.&lt;/p&gt;
&lt;p&gt;WebOb makes the `Location` header absolute when it serves a redirect. To stop a
relative or protocol-relative target from redirecting users off-host, it checks
the value for a URI scheme and for a leading `//`, then joins it against the
request URI with `urllib.parse.urljoin()`. The previous fix additionally stripped
ASCII tab/CR/LF from the value before those checks.&lt;/p&gt;
&lt;p&gt;However, on Python 3.10+ `urllib.parse.urljoin()` (via `urlsplit()`) does more
than remove tab/CR/LF: **it also strips leading and trailing C0 control
characters (`U+0000`–`U+001F`) and spaces from the URL before parsing it.**
Because WebOb&amp;#39;s guard checks (`SCHEME_RE` and `startswith(&amp;#34;//&amp;#34;)`) run against the
*un-stripped* value, a single leading space or control byte slips past them, and
`urljoin()` then silently removes that byte and parses what remains as a
protocol-relative — or even absolute — URL. The result is an open redirect to an
attacker-controlled host.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`Response._make_location_absolute()` (in `src/webob/response.py`) performed,
prior to the fix:&lt;/p&gt;
&lt;p&gt;```python
value = value.replace(&amp;#34;\t&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\r&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\n&amp;#34;, &amp;#34;&amp;#34;)&lt;/p&gt;
&lt;p&gt;if SCHEME_RE.search(value):          # ^[a-z]+:   -&amp;gt; already absolute, return as-is
    return value&lt;/p&gt;
&lt;p&gt;if value.startswith(&amp;#34;//&amp;#34;):           # neutralize protocol-relative URLs
    value = f&amp;#34;/%2f{value[2:]}&amp;#34;&lt;/p&gt;
&lt;p&gt;new_location = urlparse.urljoin(_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: webob&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;This is a third follow-up to **CVE-2024-42353 / GHSA-mg3v-6m49-jhp3**
and **CVE-2026-44889 / GHSA-fh3h-vg37-cc95**.&lt;/p&gt;
&lt;p&gt;WebOb makes the `Location` header absolute when it serves a redirect. To stop a
relative or protocol-relative target from redirecting users off-host, it checks
the value for a URI scheme and for a leading `//`, then joins it against the
request URI with `urllib.parse.urljoin()`. The previous fix additionally stripped
ASCII tab/CR/LF from the value before those checks.&lt;/p&gt;
&lt;p&gt;However, on Python 3.10+ `urllib.parse.urljoin()` (via `urlsplit()`) does more
than remove tab/CR/LF: **it also strips leading and trailing C0 control
characters (`U+0000`–`U+001F`) and spaces from the URL before parsing it.**
Because WebOb&amp;#39;s guard checks (`SCHEME_RE` and `startswith(&amp;#34;//&amp;#34;)`) run against the
*un-stripped* value, a single leading space or control byte slips past them, and
`urljoin()` then silently removes that byte and parses what remains as a
protocol-relative — or even absolute — URL. The result is an open redirect to an
attacker-controlled host.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`Response._make_location_absolute()` (in `src/webob/response.py`) performed,
prior to the fix:&lt;/p&gt;
&lt;p&gt;```python
value = value.replace(&amp;#34;\t&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\r&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\n&amp;#34;, &amp;#34;&amp;#34;)&lt;/p&gt;
&lt;p&gt;if SCHEME_RE.search(value):          # ^[a-z]+:   -&amp;gt; already absolute, return as-is
    return value&lt;/p&gt;
&lt;p&gt;if value.startswith(&amp;#34;//&amp;#34;):           # neutralize protocol-relative URLs
    value = f&amp;#34;/%2f{value[2:]}&amp;#34;&lt;/p&gt;
&lt;p&gt;new_location = urlparse.urljoin(_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6hx8-3wjj-gr8g</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-54770 — WebOb: Open redirect in Location header normalization via leading C0 control / space characters</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-54770</link>
      <description>msrc_CVE-2026-54770</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-54770</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11864-1 — python-WebOb-doc-1.8.11-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11864-1</link>
      <description>&lt;p&gt;python-WebOb-doc-1.8.11-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-WebOb-doc-1.8.11-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11864-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3943 — WebOb: Open redirect in Location header normalization via leading C0 control / space characters</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3943</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: webob&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;This is a third follow-up to **CVE-2024-42353 / GHSA-mg3v-6m49-jhp3**
and **CVE-2026-44889 / GHSA-fh3h-vg37-cc95**.&lt;/p&gt;
&lt;p&gt;WebOb makes the `Location` header absolute when it serves a redirect. To stop a
relative or protocol-relative target from redirecting users off-host, it checks
the value for a URI scheme and for a leading `//`, then joins it against the
request URI with `urllib.parse.urljoin()`. The previous fix additionally stripped
ASCII tab/CR/LF from the value before those checks.&lt;/p&gt;
&lt;p&gt;However, on Python 3.10+ `urllib.parse.urljoin()` (via `urlsplit()`) does more
than remove tab/CR/LF: **it also strips leading and trailing C0 control
characters (`U+0000`–`U+001F`) and spaces from the URL before parsing it.**
Because WebOb&amp;#39;s guard checks (`SCHEME_RE` and `startswith(&amp;#34;//&amp;#34;)`) run against the
*un-stripped* value, a single leading space or control byte slips past them, and
`urljoin()` then silently removes that byte and parses what remains as a
protocol-relative — or even absolute — URL. The result is an open redirect to an
attacker-controlled host.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`Response._make_location_absolute()` (in `src/webob/response.py`) performed,
prior to the fix:&lt;/p&gt;
&lt;p&gt;```python
value = value.replace(&amp;#34;\t&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\r&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\n&amp;#34;, &amp;#34;&amp;#34;)&lt;/p&gt;
&lt;p&gt;if SCHEME_RE.search(value):          # ^[a-z]+:   -&amp;gt; already absolute, return as-is
    return value&lt;/p&gt;
&lt;p&gt;if value.startswith(&amp;#34;//&amp;#34;):           # neutralize protocol-relative URLs
    value = f&amp;#34;/%2f{value[2:]}&amp;#34;&lt;/p&gt;
&lt;p&gt;new_location = urlparse.urljoin(_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: webob&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;This is a third follow-up to **CVE-2024-42353 / GHSA-mg3v-6m49-jhp3**
and **CVE-2026-44889 / GHSA-fh3h-vg37-cc95**.&lt;/p&gt;
&lt;p&gt;WebOb makes the `Location` header absolute when it serves a redirect. To stop a
relative or protocol-relative target from redirecting users off-host, it checks
the value for a URI scheme and for a leading `//`, then joins it against the
request URI with `urllib.parse.urljoin()`. The previous fix additionally stripped
ASCII tab/CR/LF from the value before those checks.&lt;/p&gt;
&lt;p&gt;However, on Python 3.10+ `urllib.parse.urljoin()` (via `urlsplit()`) does more
than remove tab/CR/LF: **it also strips leading and trailing C0 control
characters (`U+0000`–`U+001F`) and spaces from the URL before parsing it.**
Because WebOb&amp;#39;s guard checks (`SCHEME_RE` and `startswith(&amp;#34;//&amp;#34;)`) run against the
*un-stripped* value, a single leading space or control byte slips past them, and
`urljoin()` then silently removes that byte and parses what remains as a
protocol-relative — or even absolute — URL. The result is an open redirect to an
attacker-controlled host.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`Response._make_location_absolute()` (in `src/webob/response.py`) performed,
prior to the fix:&lt;/p&gt;
&lt;p&gt;```python
value = value.replace(&amp;#34;\t&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\r&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\n&amp;#34;, &amp;#34;&amp;#34;)&lt;/p&gt;
&lt;p&gt;if SCHEME_RE.search(value):          # ^[a-z]+:   -&amp;gt; already absolute, return as-is
    return value&lt;/p&gt;
&lt;p&gt;if value.startswith(&amp;#34;//&amp;#34;):           # neutralize protocol-relative URLs
    value = f&amp;#34;/%2f{value[2:]}&amp;#34;&lt;/p&gt;
&lt;p&gt;new_location = urlparse.urljoin(_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3943</guid>
    </item>
    <item>
      <title>RHSA-2026:69255 — Red Hat Security Advisory: Red Hat Quay 3.16.6</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:69255</link>
      <description>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request quay: mirror-registry: SSRF: repo-level mirror accepts external_reference without URL validation fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency quay: quay: Global read-only superuser can view robot account tokens crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal golang: Go os.Root: Symlink following vulnerability allows directory traversal tmp: path Traversal via unsanitized prefix/postfix enables directory escape soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files webob: WebOb: Open redirect vulnerability leading to phishing and token theft python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request quay: mirror-registry: SSRF: repo-level mirror accepts external_reference without URL validation fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency quay: quay: Global read-only superuser can view robot account tokens crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal golang: Go os.Root: Symlink following vulnerability allows directory traversal tmp: path Traversal via unsanitized prefix/postfix enables directory escape soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files webob: WebOb: Open redirect vulnerability leading to phishing and token theft python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:69255</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:4351-1 — Security update for python-WebOb</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:4351-1</link>
      <description>&lt;p&gt;Security update for python-WebOb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-WebOb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:4351-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54770</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54770</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-webob, Ubuntu:Pro:18.04:LTS: python-webob, Ubuntu:Pro:20.04:LTS: python-webob, Ubuntu:22.04:LTS: python-webob, Ubuntu:24.04:LTS: python-webob, Ubuntu:26.04:LTS: python-webob&lt;/p&gt;
&lt;p&gt;WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled value such as a space followed by a protocol-relative or absolute URL can therefore bypass SCHEME_RE and startswith(&amp;#34;//&amp;#34;) checks and be normalized to an off-host redirect. Request.relative_url() and webob.exc._HTTPMove subclasses, including HTTPFound, are also affected because they use the same unsafe URL joining behavior or bypass the earlier normalization path. An unauthenticated attacker who can influence an application&amp;#39;s redirect target can send users to an attacker-controlled host for phishing or OAuth and SSO token theft, but exploitation requires the user to follow the redirect. This issue is fixed in version 1.8.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-webob, Ubuntu:Pro:18.04:LTS: python-webob, Ubuntu:Pro:20.04:LTS: python-webob, Ubuntu:22.04:LTS: python-webob, Ubuntu:24.04:LTS: python-webob, Ubuntu:26.04:LTS: python-webob&lt;/p&gt;
&lt;p&gt;WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled value such as a space followed by a protocol-relative or absolute URL can therefore bypass SCHEME_RE and startswith(&amp;#34;//&amp;#34;) checks and be normalized to an off-host redirect. Request.relative_url() and webob.exc._HTTPMove subclasses, including HTTPFound, are also affected because they use the same unsafe URL joining behavior or bypass the earlier normalization path. An unauthenticated attacker who can influence an application&amp;#39;s redirect target can send users to an attacker-controlled host for phishing or OAuth and SSO token theft, but exploitation requires the user to follow the redirect. This issue is fixed in version 1.8.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54770</guid>
    </item>
  </channel>
</rss>
