<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:02:52 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05632</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05632</link>
      <description>bdu:2026-05632</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05632</guid>
    </item>
    <item>
      <title>EUVD-2026-337331</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337331</link>
      <description>EUVD-2026-337331</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337331</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33805</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33805</link>
      <description>&lt;p&gt;@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client&amp;#39;s Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection header value. Any header added by the proxy for routing, access control, or security purposes can be selectively removed by a client. @fastify/http-proxy is also affected as it delegates to @fastify/reply-from.&lt;/p&gt;
&lt;p&gt;Upgrade to @fastify/reply-from v12.6.2 or @fastify/http-proxy v11.4.4 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client&amp;#39;s Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection header value. Any header added by the proxy for routing, access control, or security purposes can be selectively removed by a client. @fastify/http-proxy is also affected as it delegates to @fastify/reply-from.&lt;/p&gt;
&lt;p&gt;Upgrade to @fastify/reply-from v12.6.2 or @fastify/http-proxy v11.4.4 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33805</guid>
    </item>
    <item>
      <title>GHSA-gwhp-pf74-vj37 — Fastify's connection header abuse enables stripping of proxy-added headers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gwhp-pf74-vj37</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fastify/reply-from, npm: @fastify/http-proxy&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`@fastify/reply-from` and `@fastify/http-proxy` process the client&amp;#39;s `Connection` header after the proxy has added its own headers via `rewriteRequestHeaders`. This allows attackers to retroactively strip proxy-added headers (like access control or identification headers) from upstream requests by listing them in the `Connection` header value. This affects applications using these plugins with custom header injection for routing, access control, or security purposes.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in `@fastify/reply-from/lib/request.js` at lines 128-136 (HTTP/1.1 handler) and lines 191-200 (undici handler). The processing flow is:&lt;/p&gt;
&lt;p&gt;1. Client headers are copied including the `connection` header (`@fastify/reply-from/index.js` line 91)
2. The proxy adds custom headers via `rewriteRequestHeaders` (line 151)
3. During request construction, the transport handlers read the client&amp;#39;s `Connection` header and strip any headers listed in it
4. This stripping happens after `rewriteRequestHeaders`, allowing clients to target proxy-added headers for removal&lt;/p&gt;
&lt;p&gt;RFC 7230 Section 6.1 Connection header processing is intended for proxies to strip hop-by-hop headers from incoming requests before adding their own headers. The current implementation reverses this order, processing the client&amp;#39;s Connection header after the proxy has already modified the header set.&lt;/p&gt;
&lt;p&gt;The call chain:
1. `@fastify/reply-from/index.js` line 91: `headers = { ...req.headers }` — copies ALL client heade…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fastify/reply-from, npm: @fastify/http-proxy&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`@fastify/reply-from` and `@fastify/http-proxy` process the client&amp;#39;s `Connection` header after the proxy has added its own headers via `rewriteRequestHeaders`. This allows attackers to retroactively strip proxy-added headers (like access control or identification headers) from upstream requests by listing them in the `Connection` header value. This affects applications using these plugins with custom header injection for routing, access control, or security purposes.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in `@fastify/reply-from/lib/request.js` at lines 128-136 (HTTP/1.1 handler) and lines 191-200 (undici handler). The processing flow is:&lt;/p&gt;
&lt;p&gt;1. Client headers are copied including the `connection` header (`@fastify/reply-from/index.js` line 91)
2. The proxy adds custom headers via `rewriteRequestHeaders` (line 151)
3. During request construction, the transport handlers read the client&amp;#39;s `Connection` header and strip any headers listed in it
4. This stripping happens after `rewriteRequestHeaders`, allowing clients to target proxy-added headers for removal&lt;/p&gt;
&lt;p&gt;RFC 7230 Section 6.1 Connection header processing is intended for proxies to strip hop-by-hop headers from incoming requests before adding their own headers. The current implementation reverses this order, processing the client&amp;#39;s Connection header after the proxy has already modified the header set.&lt;/p&gt;
&lt;p&gt;The call chain:
1. `@fastify/reply-from/index.js` line 91: `headers = { ...req.headers }` — copies ALL client heade…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gwhp-pf74-vj37</guid>
    </item>
    <item>
      <title>RHSA-2026:10175 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.27.1 Release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10175</link>
      <description>&lt;p&gt;golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10175</guid>
    </item>
  </channel>
</rss>
