<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:22:30 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-362014</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362014</link>
      <description>EUVD-2026-362014</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362014</guid>
    </item>
    <item>
      <title>fkie_cve-2026-77358</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-77358</link>
      <description>&lt;p&gt;cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In WebSocketClient::shutdown_and_close the SSL object is freed and the pointer cleared, but the subsequent WebSocket close still sends a close frame through the SSL socket stream, which holds a raw copy of the now-dangling session pointer and reads from and writes to the freed memory. The same freed-then-used ordering is reachable through the client&amp;#39;s destructor and its connect path, so ordinary teardown of a secure WebSocket connection triggers the defect. This issue is fixed in version 0.50.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In WebSocketClient::shutdown_and_close the SSL object is freed and the pointer cleared, but the subsequent WebSocket close still sends a close frame through the SSL socket stream, which holds a raw copy of the now-dangling session pointer and reads from and writes to the freed memory. The same freed-then-used ordering is reachable through the client&amp;#39;s destructor and its connect path, so ordinary teardown of a secure WebSocket connection triggers the defect. This issue is fixed in version 0.50.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-77358</guid>
    </item>
    <item>
      <title>OESA-2026-3800 — cpp-httplib security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3800</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: cpp-httplib&lt;/p&gt;
&lt;p&gt;A C++11 single-file header-only cross platform HTTP/HTTPS library. It&amp;amp;amp;apos;s extremely easy to setup. Just include httplib.h file in your code!&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, classified as critical, has been found in yhirose cpp-httplib up to version 0.33.0 and version 0.50.0. This is a CWE-416 Use After Free vulnerability in the WebSocket Client&amp;amp;apos;s shutdown_and_close function. Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code. The vulnerability impacts confidentiality, integrity, and availability.(CVE-2026-77358)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: cpp-httplib&lt;/p&gt;
&lt;p&gt;A C++11 single-file header-only cross platform HTTP/HTTPS library. It&amp;amp;amp;apos;s extremely easy to setup. Just include httplib.h file in your code!&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, classified as critical, has been found in yhirose cpp-httplib up to version 0.33.0 and version 0.50.0. This is a CWE-416 Use After Free vulnerability in the WebSocket Client&amp;amp;apos;s shutdown_and_close function. Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code. The vulnerability impacts confidentiality, integrity, and availability.(CVE-2026-77358)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3800</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-77358</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-77358</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: cpp-httplib, Ubuntu:Pro:24.04:LTS: cpp-httplib, Ubuntu:Pro:26.04:LTS: cpp-httplib&lt;/p&gt;
&lt;p&gt;cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In WebSocketClient::shutdown_and_close the SSL object is freed and the pointer cleared, but the subsequent WebSocket close still sends a close frame through the SSL socket stream, which holds a raw copy of the now-dangling session pointer and reads from and writes to the freed memory. The same freed-then-used ordering is reachable through the client&amp;#39;s destructor and its connect path, so ordinary teardown of a secure WebSocket connection triggers the defect. This issue is fixed in version 0.50.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: cpp-httplib, Ubuntu:Pro:24.04:LTS: cpp-httplib, Ubuntu:Pro:26.04:LTS: cpp-httplib&lt;/p&gt;
&lt;p&gt;cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In WebSocketClient::shutdown_and_close the SSL object is freed and the pointer cleared, but the subsequent WebSocket close still sends a close frame through the SSL socket stream, which holds a raw copy of the now-dangling session pointer and reads from and writes to the freed memory. The same freed-then-used ordering is reachable through the client&amp;#39;s destructor and its connect path, so ordinary teardown of a secure WebSocket connection triggers the defect. This issue is fixed in version 0.50.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-77358</guid>
    </item>
  </channel>
</rss>
