<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:07:59 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05097</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05097</link>
      <description>bdu:2026-05097</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05097</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0500 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</link>
      <description>certfr-2026-avi-0500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD27625 — Security fixes for CVE-2022-25881, CVE-2022-33987, CVE-2025-25285, CVE-2025-62718, CVE-2025-69873, CVE-2026-21637, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</guid>
    </item>
    <item>
      <title>EUVD-2026-366074</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366074</link>
      <description>EUVD-2026-366074</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366074</guid>
    </item>
    <item>
      <title>fkie_cve-2025-62718</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-62718</link>
      <description>&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0 and 0.31.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0 and 0.31.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-62718</guid>
    </item>
    <item>
      <title>GHSA-3p68-rc4w-qgx5 — Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3p68-rc4w-qgx5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;Axios does not correctly handle hostname normalization when checking `NO_PROXY` rules.
Requests to loopback addresses like `localhost.` (with a trailing dot) or `[::1]` (IPv6 literal) skip `NO_PROXY` matching and go through the configured proxy.&lt;/p&gt;
&lt;p&gt;This goes against what developers expect and lets attackers force requests through a proxy, even if `NO_PROXY` is set up to protect loopback or internal services.&lt;/p&gt;
&lt;p&gt;According to [RFC 1034 §3.1](https://datatracker.ietf.org/doc/html/rfc1034#section-3.1) and [RFC 3986 §3.2.2](https://datatracker.ietf.org/doc/html/rfc3986#section-3.2.2), a hostname can have a trailing dot to show it is a fully qualified domain name (FQDN). At the DNS level, `localhost.` is the same as `localhost`. 
However, Axios does a literal string comparison instead of normalizing hostnames before checking `NO_PROXY`. This causes requests like `http://localhost.:8080/` and `http://[::1]:8080/` to be incorrectly proxied.&lt;/p&gt;
&lt;p&gt;This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;**PoC**&lt;/p&gt;
&lt;p&gt;```js
import http from &amp;#34;http&amp;#34;;
import axios from &amp;#34;axios&amp;#34;;&lt;/p&gt;
&lt;p&gt;const proxyPort = 5300;&lt;/p&gt;
&lt;p&gt;http.createServer((req, res) =&amp;gt; {
  console.log(&amp;#34;[PROXY] Got:&amp;#34;, req.method, req.url, &amp;#34;Host:&amp;#34;, req.headers.host);
  res.writeHead(200, { &amp;#34;Content-Type&amp;#34;: &amp;#34;text/plain&amp;#34; });
  res.end(&amp;#34;proxied&amp;#34;);
}).listen(proxyPort, () =&amp;gt; console.log(&amp;#34;Proxy&amp;#34;, proxyPort));&lt;/p&gt;
&lt;p&gt;process.env.HTTP_PROXY…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;Axios does not correctly handle hostname normalization when checking `NO_PROXY` rules.
Requests to loopback addresses like `localhost.` (with a trailing dot) or `[::1]` (IPv6 literal) skip `NO_PROXY` matching and go through the configured proxy.&lt;/p&gt;
&lt;p&gt;This goes against what developers expect and lets attackers force requests through a proxy, even if `NO_PROXY` is set up to protect loopback or internal services.&lt;/p&gt;
&lt;p&gt;According to [RFC 1034 §3.1](https://datatracker.ietf.org/doc/html/rfc1034#section-3.1) and [RFC 3986 §3.2.2](https://datatracker.ietf.org/doc/html/rfc3986#section-3.2.2), a hostname can have a trailing dot to show it is a fully qualified domain name (FQDN). At the DNS level, `localhost.` is the same as `localhost`. 
However, Axios does a literal string comparison instead of normalizing hostnames before checking `NO_PROXY`. This causes requests like `http://localhost.:8080/` and `http://[::1]:8080/` to be incorrectly proxied.&lt;/p&gt;
&lt;p&gt;This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;**PoC**&lt;/p&gt;
&lt;p&gt;```js
import http from &amp;#34;http&amp;#34;;
import axios from &amp;#34;axios&amp;#34;;&lt;/p&gt;
&lt;p&gt;const proxyPort = 5300;&lt;/p&gt;
&lt;p&gt;http.createServer((req, res) =&amp;gt; {
  console.log(&amp;#34;[PROXY] Got:&amp;#34;, req.method, req.url, &amp;#34;Host:&amp;#34;, req.headers.host);
  res.writeHead(200, { &amp;#34;Content-Type&amp;#34;: &amp;#34;text/plain&amp;#34; });
  res.end(&amp;#34;proxied&amp;#34;);
}).listen(proxyPort, () =&amp;gt; console.log(&amp;#34;Proxy&amp;#34;, proxyPort));&lt;/p&gt;
&lt;p&gt;process.env.HTTP_PROXY…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3p68-rc4w-qgx5</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-62718 — Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-62718</link>
      <description>msrc_CVE-2025-62718</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-62718</guid>
    </item>
    <item>
      <title>RHSA-2026:10175 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.27.1 Release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10175</link>
      <description>&lt;p&gt;golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10175</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-62718</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-62718</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:25.10: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0 and 0.31.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:25.10: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0 and 0.31.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-62718</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1157 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1157</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting durchzuführen und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting durchzuführen und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1157</guid>
    </item>
  </channel>
</rss>
