<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:36:01 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</link>
      <description>certfr-2026-avi-1233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EC11110 — undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier pa…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ec11110</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-superset&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-superset package. undici&amp;#39;s retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response&amp;#39;s status and headers. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-superset&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-superset package. undici&amp;#39;s retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response&amp;#39;s status and headers. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ec11110</guid>
    </item>
    <item>
      <title>EUVD-2026-364000</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364000</link>
      <description>EUVD-2026-364000</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364000</guid>
    </item>
    <item>
      <title>fkie_cve-2026-18540</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-18540</link>
      <description>&lt;p&gt;undici&amp;#39;s retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response&amp;#39;s status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. An application that relays such a response to a downstream HTTP/1.1 peer without normalizing the framing can emit a body that exceeds the forwarded Content-Length, and the excess bytes can be interpreted as the start of a following response, which enables downstream response splitting or desynchronization. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici&amp;#39;s retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response&amp;#39;s status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. An application that relays such a response to a downstream HTTP/1.1 peer without normalizing the framing can emit a body that exceeds the forwarded Content-Length, and the excess bytes can be interpreted as the start of a following response, which enables downstream response splitting or desynchronization. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-18540</guid>
    </item>
    <item>
      <title>GHSA-r53p-7pc4-xj5r — undici vulnerable to downstream response splitting via retry interceptor</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r53p-7pc4-xj5r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Undici&amp;#39;s `interceptors.retry()` can resume a request after a partial response and append the resumed bytes to an already partially delivered body, while the application still receives the original response&amp;#39;s status and headers. When that response carried a `Content-Length`, the application can receive a longer body. Applications that forward Undici&amp;#39;s status, headers, and body downstream without recalculating framing, for example proxy or gateway applications, may emit a response whose body exceeds the forwarded `Content-Length`, and the excess bytes can be read as the start of a subsequent HTTP response (downstream response splitting or desynchronization).&lt;/p&gt;
&lt;p&gt;For example, a `404 Not Found` with `Content-Length: 2` that sends one byte then closes can be resumed with an open-ended `Range` request, and the resumed `206 Partial Content` bytes are appended, so the application receives more than two body bytes while still seeing `Content-Length: 2`. The bug requires `interceptors.retry()` enabled, an attacker-controlled or faulty upstream, and a downstream forwarder that does not recalculate `Content-Length`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patched in undici v6.28.1, v7.29.1, and v8.10.2. Upgrade to one of these or later.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;- Disable `interceptors.retry()` for untrusted upstreams, or set `maxRetries: 0`.
- Remove or recalculate `Content-Length` before forwarding a response body assembled by Undici.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Undici&amp;#39;s `interceptors.retry()` can resume a request after a partial response and append the resumed bytes to an already partially delivered body, while the application still receives the original response&amp;#39;s status and headers. When that response carried a `Content-Length`, the application can receive a longer body. Applications that forward Undici&amp;#39;s status, headers, and body downstream without recalculating framing, for example proxy or gateway applications, may emit a response whose body exceeds the forwarded `Content-Length`, and the excess bytes can be read as the start of a subsequent HTTP response (downstream response splitting or desynchronization).&lt;/p&gt;
&lt;p&gt;For example, a `404 Not Found` with `Content-Length: 2` that sends one byte then closes can be resumed with an open-ended `Range` request, and the resumed `206 Partial Content` bytes are appended, so the application receives more than two body bytes while still seeing `Content-Length: 2`. The bug requires `interceptors.retry()` enabled, an attacker-controlled or faulty upstream, and a downstream forwarder that does not recalculate `Content-Length`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patched in undici v6.28.1, v7.29.1, and v8.10.2. Upgrade to one of these or later.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;- Disable `interceptors.retry()` for untrusted upstreams, or set `maxRetries: 0`.
- Remove or recalculate `Content-Length` before forwarding a response body assembled by Undici.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r53p-7pc4-xj5r</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-18540 — undici vulnerable to downstream response splitting via retry interceptor</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-18540</link>
      <description>msrc_CVE-2026-18540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-18540</guid>
    </item>
    <item>
      <title>RHSA-2026:66008 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:66008</link>
      <description>&lt;p&gt;grafana: Grafana: Session takeover via Auth Proxy cache key collision undici: undici: Denial of Service due to orphaned response body in retry handler undici: undici: HTTP response splitting via retry interceptor undici: undici: Denial of Service via unrequested WebSocket subprotocol grafana: Grafana: Unauthorized public dashboard deletion across organizations undici: undici: Denial of Service via unbounded decompression of compressed responses undici: undici: Cross-user cookie disclosure via Set-Cookie caching undici: Undici: Response truncation and connection termination undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options undici: undici: Integrity failure due to caching of unsafe HTTP method responses undici: undici: Denial of Service via WebSocketStream unclean close&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana: Grafana: Session takeover via Auth Proxy cache key collision undici: undici: Denial of Service due to orphaned response body in retry handler undici: undici: HTTP response splitting via retry interceptor undici: undici: Denial of Service via unrequested WebSocket subprotocol grafana: Grafana: Unauthorized public dashboard deletion across organizations undici: undici: Denial of Service via unbounded decompression of compressed responses undici: undici: Cross-user cookie disclosure via Set-Cookie caching undici: Undici: Response truncation and connection termination undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options undici: undici: Integrity failure due to caching of unsafe HTTP method responses undici: undici: Denial of Service via WebSocketStream unclean close&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:66008</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-18540</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18540</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;undici&amp;#39;s retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response&amp;#39;s status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. An application that relays such a response to a downstream HTTP/1.1 peer without normalizing the framing can emit a body that exceeds the forwarded Content-Length, and the excess bytes can be interpreted as the start of a following response, which enables downstream response splitting or desynchronization. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;undici&amp;#39;s retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response&amp;#39;s status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. An application that relays such a response to a downstream HTTP/1.1 peer without normalizing the framing can emit a body that exceeds the forwarded Content-Length, and the excess bytes can be interpreted as the start of a following response, which enables downstream response splitting or desynchronization. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18540</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
