<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 08:53:11 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-0636 — LDAP Injection Vulnerability in LDAPStoreHelper.java</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-0636</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Legion of the Bouncy Castle Inc. BC-JAVA, Red Hat AMQ Broker 7.12.7, Red Hat AMQ Broker 7.13.5, Red Hat AMQ Broker 7.14.1, Red Hat Build of Apache Camel 4.14 for Quarkus 3.27, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat build of Quarkus 3.20.6.SP1, Red Hat build of Quarkus 3.27.3.SP1, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8 and 35 more&lt;/p&gt;
&lt;p&gt;Improper neutralization of special elements used in an LDAP query (&amp;#39;LDAP injection&amp;#39;) vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files LDAPStoreHelper.&lt;/p&gt;
&lt;p&gt;This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Legion of the Bouncy Castle Inc. BC-JAVA, Red Hat AMQ Broker 7.12.7, Red Hat AMQ Broker 7.13.5, Red Hat AMQ Broker 7.14.1, Red Hat Build of Apache Camel 4.14 for Quarkus 3.27, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat build of Quarkus 3.20.6.SP1, Red Hat build of Quarkus 3.27.3.SP1, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8 and 35 more&lt;/p&gt;
&lt;p&gt;Improper neutralization of special elements used in an LDAP query (&amp;#39;LDAP injection&amp;#39;) vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files LDAPStoreHelper.&lt;/p&gt;
&lt;p&gt;This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-0636</guid>
    </item>
    <item>
      <title>GHSA-355h-qmc2-wpwf — Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-355h-qmc2-wpwf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty:jetty-http&lt;/p&gt;
&lt;p&gt;### Description (as reported)&lt;/p&gt;
&lt;p&gt;Jetty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks.&lt;/p&gt;
&lt;p&gt;### Background&lt;/p&gt;
&lt;p&gt;This vulnerability is a new variant discovered while researching the &amp;#34;Funky Chunks&amp;#34; HTTP request smuggling techniques:
- https://w4ke.info/2025/06/18/funky-chunks.html
- https://w4ke.info/2025/10/29/funky-chunks-2.html&lt;/p&gt;
&lt;p&gt;The original research tested various chunk extension parsing differentials but did not test quoted-string handling within extension values.&lt;/p&gt;
&lt;p&gt;### Technical Details&lt;/p&gt;
&lt;p&gt;**RFC 9112 Section 7.1.1** defines chunked transfer encoding:
```
chunk = chunk-size [ chunk-ext ] CRLF chunk-data CRLF
chunk-ext = *( BWS &amp;#34;;&amp;#34; BWS chunk-ext-name [ BWS &amp;#34;=&amp;#34; BWS chunk-ext-val ] )
chunk-ext-val = token / quoted-string
```&lt;/p&gt;
&lt;p&gt;**RFC 9110 Section 5.6.4** defines quoted-string:
```
quoted-string = DQUOTE *( qdtext / quoted-pair ) DQUOTE
```&lt;/p&gt;
&lt;p&gt;A quoted-string continues until the closing DQUOTE, and `\r\n` sequences are not permitted within the quotes.&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;Jetty terminates chunk header parsing at `\r\n` inside quoted strings instead of treating this as an error.&lt;/p&gt;
&lt;p&gt;**Expected (RFC compliant):**
```
Chunk: 1;a=&amp;#34;value\r\nhere&amp;#34;\r\n
         ^^^^^^^^^^^^^^^^^^ extension value
Body: [1 byte after the real \r\n]
```&lt;/p&gt;
&lt;p&gt;**Actual (jetty):**
```
Chunk: 1;a=&amp;#34;value
            ^^^^^ terminates here (WRONG)
Body: here&amp;#34;... treated as body/next request
```&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;```python
#!/usr/bin/env python3
import…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty:jetty-http&lt;/p&gt;
&lt;p&gt;### Description (as reported)&lt;/p&gt;
&lt;p&gt;Jetty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks.&lt;/p&gt;
&lt;p&gt;### Background&lt;/p&gt;
&lt;p&gt;This vulnerability is a new variant discovered while researching the &amp;#34;Funky Chunks&amp;#34; HTTP request smuggling techniques:
- https://w4ke.info/2025/06/18/funky-chunks.html
- https://w4ke.info/2025/10/29/funky-chunks-2.html&lt;/p&gt;
&lt;p&gt;The original research tested various chunk extension parsing differentials but did not test quoted-string handling within extension values.&lt;/p&gt;
&lt;p&gt;### Technical Details&lt;/p&gt;
&lt;p&gt;**RFC 9112 Section 7.1.1** defines chunked transfer encoding:
```
chunk = chunk-size [ chunk-ext ] CRLF chunk-data CRLF
chunk-ext = *( BWS &amp;#34;;&amp;#34; BWS chunk-ext-name [ BWS &amp;#34;=&amp;#34; BWS chunk-ext-val ] )
chunk-ext-val = token / quoted-string
```&lt;/p&gt;
&lt;p&gt;**RFC 9110 Section 5.6.4** defines quoted-string:
```
quoted-string = DQUOTE *( qdtext / quoted-pair ) DQUOTE
```&lt;/p&gt;
&lt;p&gt;A quoted-string continues until the closing DQUOTE, and `\r\n` sequences are not permitted within the quotes.&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;Jetty terminates chunk header parsing at `\r\n` inside quoted strings instead of treating this as an error.&lt;/p&gt;
&lt;p&gt;**Expected (RFC compliant):**
```
Chunk: 1;a=&amp;#34;value\r\nhere&amp;#34;\r\n
         ^^^^^^^^^^^^^^^^^^ extension value
Body: [1 byte after the real \r\n]
```&lt;/p&gt;
&lt;p&gt;**Actual (jetty):**
```
Chunk: 1;a=&amp;#34;value
            ^^^^^ terminates here (WRONG)
Body: here&amp;#34;... treated as body/next request
```&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;```python
#!/usr/bin/env python3
import…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-355h-qmc2-wpwf</guid>
    </item>
  </channel>
</rss>
