<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:22:49 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-AV60851 — Security fix for CVE-2026-71849 applied in: langfuse 3.208.0-r1, langfuse 3.213.0-r1, langfuse 4.10.0-r1, langfuse 4.12…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-av60851</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse, CleanStart: langfuse-worker, CleanStart: n8n&lt;/p&gt;
&lt;p&gt;CVE-2026-71849 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse, CleanStart: langfuse-worker, CleanStart: n8n&lt;/p&gt;
&lt;p&gt;CVE-2026-71849 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-av60851</guid>
    </item>
    <item>
      <title>EUVD-2026-349691</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349691</link>
      <description>EUVD-2026-349691</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349691</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71849</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71849</link>
      <description>&lt;p&gt;Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin&amp;#39;s Connection header. Per RFC 9110 Section 7.6.1, an intermediary must remove the header fields listed in a message&amp;#39;s Connection header field before forwarding the message, in addition to the well known hop by hop headers, but the proxy() function only removed the well known hop by hop headers, including Connection itself, from origin responses. A client may therefore receive response headers that the origin intended only for its immediate peer, disclosing connection scoped or internal metadata contained in such headers, when an application proxies responses from an origin that declares additional, non standard headers as hop by hop via the Connection response header. This issue is fixed in version 4.12.34.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin&amp;#39;s Connection header. Per RFC 9110 Section 7.6.1, an intermediary must remove the header fields listed in a message&amp;#39;s Connection header field before forwarding the message, in addition to the well known hop by hop headers, but the proxy() function only removed the well known hop by hop headers, including Connection itself, from origin responses. A client may therefore receive response headers that the origin intended only for its immediate peer, disclosing connection scoped or internal metadata contained in such headers, when an application proxies responses from an origin that declares additional, non standard headers as hop by hop via the Connection response header. This issue is fixed in version 4.12.34.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71849</guid>
    </item>
    <item>
      <title>GHSA-79qm-7rj5-m7r9 — Hono: Proxy Helper does not remove response headers listed in the `Connection` header</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-79qm-7rj5-m7r9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: hono&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Proxy Helper (`hono/proxy`) does not remove response headers named by the origin&amp;#39;s `Connection` header. Headers that the origin marked as connection-scoped are therefore forwarded to clients.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Per RFC 9110 Section 7.6.1, an intermediary must remove the header fields listed in a message&amp;#39;s `Connection` header field before forwarding the message, in addition to the well-known hop-by-hop headers. The `proxy()` function removed the well-known hop-by-hop headers (including `Connection` itself) from origin responses, but did not remove the headers that the response&amp;#39;s `Connection` header field designated as connection-scoped.&lt;/p&gt;
&lt;p&gt;This issue arises when an application proxies responses from an origin that declares additional, non-standard headers as hop-by-hop via the `Connection` response header.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A client may receive response headers that the origin intended only for its immediate peer. This may lead to:&lt;/p&gt;
&lt;p&gt;- Disclosure of connection-scoped or internal metadata contained in such headers&lt;/p&gt;
&lt;p&gt;This issue affects applications that use the Proxy Helper (`hono/proxy`) to forward responses from origins that list custom header names in their `Connection` response header. Applications whose origins only use the standard hop-by-hop headers are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: hono&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Proxy Helper (`hono/proxy`) does not remove response headers named by the origin&amp;#39;s `Connection` header. Headers that the origin marked as connection-scoped are therefore forwarded to clients.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Per RFC 9110 Section 7.6.1, an intermediary must remove the header fields listed in a message&amp;#39;s `Connection` header field before forwarding the message, in addition to the well-known hop-by-hop headers. The `proxy()` function removed the well-known hop-by-hop headers (including `Connection` itself) from origin responses, but did not remove the headers that the response&amp;#39;s `Connection` header field designated as connection-scoped.&lt;/p&gt;
&lt;p&gt;This issue arises when an application proxies responses from an origin that declares additional, non-standard headers as hop-by-hop via the `Connection` response header.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A client may receive response headers that the origin intended only for its immediate peer. This may lead to:&lt;/p&gt;
&lt;p&gt;- Disclosure of connection-scoped or internal metadata contained in such headers&lt;/p&gt;
&lt;p&gt;This issue affects applications that use the Proxy Helper (`hono/proxy`) to forward responses from origins that list custom header names in their `Connection` response header. Applications whose origins only use the standard hop-by-hop headers are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-79qm-7rj5-m7r9</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3221 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3221</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3221</guid>
    </item>
  </channel>
</rss>
