<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:03:44 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0846 — De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0846</link>
      <description>certfr-2026-avi-0846</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0846</guid>
    </item>
    <item>
      <title>EUVD-2026-322111</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322111</link>
      <description>EUVD-2026-322111</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322111</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39806</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39806</link>
      <description>&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion.&lt;/p&gt;
&lt;p&gt;&amp;#39;Elixir.Bandit.HTTP1.Socket&amp;#39;:do_read_chunked_data!/5 in lib/bandit/http1/socket.ex terminates only when the last-chunk line 0\r\n is followed immediately by the empty trailer line \r\n. RFC 9112 §7.1.2 permits zero or more trailer fields between them. When trailers are present, none of the match clauses fit: the catch-all arm computes a negative to_read, calls read_available!/2, receives &amp;lt;&amp;lt;&amp;gt;&amp;gt; on timeout, and tail-recurses with unchanged state. The worker process is pinned for the lifetime of the TCP connection.&lt;/p&gt;
&lt;p&gt;A handful of concurrent connections sending RFC-conformant chunked requests with trailer fields is sufficient to exhaust the Bandit worker pool and render the server unresponsive to all further traffic. No authentication, special headers, or large payload is required. Proxies such as NGINX and HAProxy legitimately forward trailer-bearing requests, so servers behind such proxies may be affected without any malicious client involvement.&lt;/p&gt;
&lt;p&gt;This issue affects bandit: from 1.6.1 before 1.11.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion.&lt;/p&gt;
&lt;p&gt;&amp;#39;Elixir.Bandit.HTTP1.Socket&amp;#39;:do_read_chunked_data!/5 in lib/bandit/http1/socket.ex terminates only when the last-chunk line 0\r\n is followed immediately by the empty trailer line \r\n. RFC 9112 §7.1.2 permits zero or more trailer fields between them. When trailers are present, none of the match clauses fit: the catch-all arm computes a negative to_read, calls read_available!/2, receives &amp;lt;&amp;lt;&amp;gt;&amp;gt; on timeout, and tail-recurses with unchanged state. The worker process is pinned for the lifetime of the TCP connection.&lt;/p&gt;
&lt;p&gt;A handful of concurrent connections sending RFC-conformant chunked requests with trailer fields is sufficient to exhaust the Bandit worker pool and render the server unresponsive to all further traffic. No authentication, special headers, or large payload is required. Proxies such as NGINX and HAProxy legitimately forward trailer-bearing requests, so servers behind such proxies may be affected without any malicious client involvement.&lt;/p&gt;
&lt;p&gt;This issue affects bandit: from 1.6.1 before 1.11.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39806</guid>
    </item>
    <item>
      <title>GHSA-rf5q-vwxw-gmrf — Bandit: Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rf5q-vwxw-gmrf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: bandit&lt;/p&gt;
&lt;p&gt;### Summary
A worker-pinning denial of service in Bandit&amp;#39;s HTTP/1 chunked transfer decoder. Any unauthenticated client that sends a `Transfer-Encoding: chunked` request whose body ends with a trailer field (RFC 9112 §7.1.2 explicitly permits this) causes the connection&amp;#39;s worker process to spin forever in an infinite recursion. A handful of concurrent connections are sufficient to exhaust the listener pool and render the server unresponsive to all further traffic.&lt;/p&gt;
&lt;p&gt;The vulnerability was likely introduced with this commit on `Dec 6, 2024`: https://github.com/mtrudel/bandit/commit/e73e379ab59840e8561b5730878f16e29ab06217&lt;/p&gt;
&lt;p&gt;### Details
The bug is in `lib/bandit/http1/socket.ex` in `do_read_chunked_data!/5` (around lines 242–274). The terminator clause matches only `[&amp;#34;0&amp;#34;, &amp;#34;\r\n&amp;#34; &amp;lt;&amp;gt; rest]` — i.e. the last-chunk line `0\r\n` followed *immediately* by the empty trailer line. RFC 9112 §7.1.2 allows zero or more trailer fields between `0\r\n` and the final `\r\n`, e.g. a body ending `0\r\nX-T: v\r\n\r\n`.&lt;/p&gt;
&lt;p&gt;When trailers are present, `:binary.split/2` returns `[&amp;#34;0&amp;#34;, &amp;#34;X-T: v\r\n\r\n&amp;#34;]`. The terminator clause does not match. The inner `&amp;lt;&amp;lt;_::binary-size(0), ?\r, ?\n, _::binary&amp;gt;&amp;gt;` pattern also does not match because `rest` starts with `X`. Execution falls into the `_ -&amp;gt;` arm, which computes `to_read = 0 - byte_size(rest)` (a negative number) and calls `read_available!/2` on the socket. On timeout, `read_available!/2` returns `&amp;lt;&amp;lt;&amp;gt;&amp;gt;`, leaving the buffer unchanged. `do_read_chunked_data!/5` th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: bandit&lt;/p&gt;
&lt;p&gt;### Summary
A worker-pinning denial of service in Bandit&amp;#39;s HTTP/1 chunked transfer decoder. Any unauthenticated client that sends a `Transfer-Encoding: chunked` request whose body ends with a trailer field (RFC 9112 §7.1.2 explicitly permits this) causes the connection&amp;#39;s worker process to spin forever in an infinite recursion. A handful of concurrent connections are sufficient to exhaust the listener pool and render the server unresponsive to all further traffic.&lt;/p&gt;
&lt;p&gt;The vulnerability was likely introduced with this commit on `Dec 6, 2024`: https://github.com/mtrudel/bandit/commit/e73e379ab59840e8561b5730878f16e29ab06217&lt;/p&gt;
&lt;p&gt;### Details
The bug is in `lib/bandit/http1/socket.ex` in `do_read_chunked_data!/5` (around lines 242–274). The terminator clause matches only `[&amp;#34;0&amp;#34;, &amp;#34;\r\n&amp;#34; &amp;lt;&amp;gt; rest]` — i.e. the last-chunk line `0\r\n` followed *immediately* by the empty trailer line. RFC 9112 §7.1.2 allows zero or more trailer fields between `0\r\n` and the final `\r\n`, e.g. a body ending `0\r\nX-T: v\r\n\r\n`.&lt;/p&gt;
&lt;p&gt;When trailers are present, `:binary.split/2` returns `[&amp;#34;0&amp;#34;, &amp;#34;X-T: v\r\n\r\n&amp;#34;]`. The terminator clause does not match. The inner `&amp;lt;&amp;lt;_::binary-size(0), ?\r, ?\n, _::binary&amp;gt;&amp;gt;` pattern also does not match because `rest` starts with `X`. Execution falls into the `_ -&amp;gt;` arm, which computes `to_read = 0 - byte_size(rest)` (a negative number) and calls `read_available!/2` on the socket. On timeout, `read_available!/2` returns `&amp;lt;&amp;lt;&amp;gt;&amp;gt;`, leaving the buffer unchanged. `do_read_chunked_data!/5` th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rf5q-vwxw-gmrf</guid>
    </item>
  </channel>
</rss>
