<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:33:58 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-1051 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1051</link>
      <description>certfr-2025-avi-1051</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1051</guid>
    </item>
    <item>
      <title>EUVD-2026-253330</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-253330</link>
      <description>EUVD-2026-253330</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-253330</guid>
    </item>
    <item>
      <title>fkie_cve-2025-59822</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59822</link>
      <description>&lt;p&gt;Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers security controls, launch targeted attacks against active users, and poison web caches. A pre-requisite for exploitation involves the web application being deployed behind a reverse-proxy that forwards trailer headers. This issue has been patched in versions 1.0.0-M45 and 0.23.31.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers security controls, launch targeted attacks against active users, and poison web caches. A pre-requisite for exploitation involves the web application being deployed behind a reverse-proxy that forwards trailer headers. This issue has been patched in versions 1.0.0-M45 and 0.23.31.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-59822</guid>
    </item>
    <item>
      <title>GHSA-wcwh-7gfw-5wrr — Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wcwh-7gfw-5wrr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.http4s:http4s-ember-core_2.12, Maven: org.http4s:http4s-ember-core_2.13, Maven: org.http4s:http4s-ember-core_3&lt;/p&gt;
&lt;p&gt;### Summary
http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section.
This vulnerability could enable attackers to:
- Bypass front-end servers security controls
- Launch targeted attacks against active users
- Poison web caches&lt;/p&gt;
&lt;p&gt;Pre-requisites for the exploitation: the web appication has to be deployed behind a reverse-proxy that forwards trailer headers.&lt;/p&gt;
&lt;p&gt;### Details
The HTTP chunked message parser, after parsing the last body chunk, calls `parseTrailers` (`ember-core/shared/src/main/scala/org/http4s/ember/core/ChunkedEncoding.scala#L122-142`).
This method parses the trailer section using `Parser.parse`, where the issue originates.&lt;/p&gt;
&lt;p&gt;`parse` has a bug that allows to terminate the parsing before finding the double CRLF condition: when it finds an header line that **does not include the colon character**, it continues parsing with `state=false` looking for the header name till reaching the condition `else if (current == lf &amp;amp;&amp;amp; (idx &amp;gt; 0 &amp;amp;&amp;amp; message(idx - 1) == cr))` that sets `complete=true` even if no `\r\n\r\n` is  found.
```scala
if (current == colon) {
  state = true // set state to check for header value
  name = new String(message, start, idx - start) // extract name string
  start = idx + 1 // advance past colon for next start&lt;/p&gt;
&lt;p&gt;// TODO: This if clause may not be necessary since the header value parser trims
  if (message.size &amp;gt; idx + 1 &amp;amp;&amp;amp; message(idx + 1) == space) {
    start += 1 // if colon is followed by space advance again…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.http4s:http4s-ember-core_2.12, Maven: org.http4s:http4s-ember-core_2.13, Maven: org.http4s:http4s-ember-core_3&lt;/p&gt;
&lt;p&gt;### Summary
http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section.
This vulnerability could enable attackers to:
- Bypass front-end servers security controls
- Launch targeted attacks against active users
- Poison web caches&lt;/p&gt;
&lt;p&gt;Pre-requisites for the exploitation: the web appication has to be deployed behind a reverse-proxy that forwards trailer headers.&lt;/p&gt;
&lt;p&gt;### Details
The HTTP chunked message parser, after parsing the last body chunk, calls `parseTrailers` (`ember-core/shared/src/main/scala/org/http4s/ember/core/ChunkedEncoding.scala#L122-142`).
This method parses the trailer section using `Parser.parse`, where the issue originates.&lt;/p&gt;
&lt;p&gt;`parse` has a bug that allows to terminate the parsing before finding the double CRLF condition: when it finds an header line that **does not include the colon character**, it continues parsing with `state=false` looking for the header name till reaching the condition `else if (current == lf &amp;amp;&amp;amp; (idx &amp;gt; 0 &amp;amp;&amp;amp; message(idx - 1) == cr))` that sets `complete=true` even if no `\r\n\r\n` is  found.
```scala
if (current == colon) {
  state = true // set state to check for header value
  name = new String(message, start, idx - start) // extract name string
  start = idx + 1 // advance past colon for next start&lt;/p&gt;
&lt;p&gt;// TODO: This if clause may not be necessary since the header value parser trims
  if (message.size &amp;gt; idx + 1 &amp;amp;&amp;amp; message(idx + 1) == space) {
    start += 1 // if colon is followed by space advance again…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wcwh-7gfw-5wrr</guid>
    </item>
  </channel>
</rss>
