<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 21:00:30 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-05797</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05797</link>
      <description>bdu:2024-05797</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05797</guid>
    </item>
    <item>
      <title>cnvd-2024-35169</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-35169</link>
      <description>cnvd-2024-35169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-35169</guid>
    </item>
    <item>
      <title>EUVD-2026-258452</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258452</link>
      <description>EUVD-2026-258452</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258452</guid>
    </item>
    <item>
      <title>fkie_cve-2023-38522</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-38522</link>
      <description>&lt;p&gt;Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-38522</guid>
    </item>
    <item>
      <title>GHSA-68qf-xhq3-9qj5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-68qf-xhq3-9qj5</link>
      <description>&lt;p&gt;Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-68qf-xhq3-9qj5</guid>
    </item>
    <item>
      <title>gsd-2023-38522</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-38522</link>
      <description>gsd-2023-38522</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-38522</guid>
    </item>
    <item>
      <title>OESA-2024-1955 — trafficserver security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1955</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: trafficserver&lt;/p&gt;
&lt;p&gt;Apache Traffic Server is an OpenSource HTTP / HTTPS / HTTP/2 / QUIC reverse, forward and transparent proxy and cache.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.&#13;
&#13;
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.&#13;
&#13;
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.(CVE-2023-38522)&#13;
&#13;
Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.&#13;
&#13;
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.&#13;
&#13;
Users can set a new setting (proxy.config.http.drop_chunked_trailers) not to forward chunked trailer section.
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.(CVE-2024-35161)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: trafficserver&lt;/p&gt;
&lt;p&gt;Apache Traffic Server is an OpenSource HTTP / HTTPS / HTTP/2 / QUIC reverse, forward and transparent proxy and cache.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.&#13;
&#13;
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.&#13;
&#13;
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.(CVE-2023-38522)&#13;
&#13;
Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.&#13;
&#13;
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.&#13;
&#13;
Users can set a new setting (proxy.config.http.drop_chunked_trailers) not to forward chunked trailer section.
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.(CVE-2024-35161)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1955</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-38522</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38522</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: trafficserver, Ubuntu:18.04:LTS: trafficserver, Ubuntu:Pro:20.04:LTS: trafficserver, Ubuntu:Pro:22.04:LTS: trafficserver, Ubuntu:24.04:LTS: trafficserver&lt;/p&gt;
&lt;p&gt;Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: trafficserver, Ubuntu:18.04:LTS: trafficserver, Ubuntu:Pro:20.04:LTS: trafficserver, Ubuntu:Pro:22.04:LTS: trafficserver, Ubuntu:24.04:LTS: trafficserver&lt;/p&gt;
&lt;p&gt;Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-38522</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1713 — Apache Traffic Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1713</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache Traffic Server ausnutzen, um einen Denial of Service Angriff durchzuführen oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache Traffic Server ausnutzen, um einen Denial of Service Angriff durchzuführen oder Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1713</guid>
    </item>
  </channel>
</rss>
