<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:05:14 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-325584</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-325584</link>
      <description>EUVD-2026-325584</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-325584</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49756</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49756</link>
      <description>&lt;p&gt;Improper Neutralization of CRLF Sequences (&amp;#39;CRLF Injection&amp;#39;) vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata.&lt;/p&gt;
&lt;p&gt;Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part headers by interpolating the caller-supplied name, filename, and content_type values directly into the content-disposition and content-type lines with no escaping or CRLF stripping. A value containing &amp;#34;, \r, or \n closes the surrounding quoted value and starts a new header line; an additional \r\n--&amp;lt;boundary&amp;gt; terminates the current part and prepends a smuggled part of the attacker&amp;#39;s choosing.&lt;/p&gt;
&lt;p&gt;This is reachable through every supported way of supplying a part. It is particularly easy when value is a %File.Stream{}, because filename then defaults to Path.basename(stream.path) and POSIX filenames may legitimately contain \r and \n. Any application that forwards user-controlled filenames (or field names / MIME types) through Req.post/2 with form_multipart: lets an attacker inject arbitrary headers into the outgoing multipart body or smuggle additional fields and parts into the request the victim service sends downstream.&lt;/p&gt;
&lt;p&gt;This issue affects req: from 0.5.3 before 0.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Neutralization of CRLF Sequences (&amp;#39;CRLF Injection&amp;#39;) vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata.&lt;/p&gt;
&lt;p&gt;Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part headers by interpolating the caller-supplied name, filename, and content_type values directly into the content-disposition and content-type lines with no escaping or CRLF stripping. A value containing &amp;#34;, \r, or \n closes the surrounding quoted value and starts a new header line; an additional \r\n--&amp;lt;boundary&amp;gt; terminates the current part and prepends a smuggled part of the attacker&amp;#39;s choosing.&lt;/p&gt;
&lt;p&gt;This is reachable through every supported way of supplying a part. It is particularly easy when value is a %File.Stream{}, because filename then defaults to Path.basename(stream.path) and POSIX filenames may legitimately contain \r and \n. Any application that forwards user-controlled filenames (or field names / MIME types) through Req.post/2 with form_multipart: lets an attacker inject arbitrary headers into the outgoing multipart body or smuggle additional fields and parts into the request the victim service sends downstream.&lt;/p&gt;
&lt;p&gt;This issue affects req: from 0.5.3 before 0.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49756</guid>
    </item>
    <item>
      <title>GHSA-px9f-whj3-246m — Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-px9f-whj3-246m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: req&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Req&amp;#39;s multipart form encoder interpolates the per-part `name`, `filename`, and `content_type` directly into the part headers without escaping. An attacker who can influence any of those values can inject CRLF-separated header lines, smuggle additional form fields, or prepend a whole extra part into the request the victim service sends downstream.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`Req.Utils.encode_form_part/2` in `lib/req/utils.ex` builds the per-part header iodata by concatenating the three caller-supplied strings verbatim into `content-disposition: form-data; name=&amp;#34;&amp;lt;name&amp;gt;&amp;#34;; filename=&amp;#34;&amp;lt;filename&amp;gt;&amp;#34;` and `content-type: &amp;lt;content_type&amp;gt;`. There is no CRLF stripping, no quote escaping, and no validation. A value containing `&amp;#34;\r\n` closes the surrounding quoted value and starts a new header line; an additional `\r\n--&amp;lt;boundary&amp;gt;` terminates the current part and lets the attacker prepend a smuggled part.&lt;/p&gt;
&lt;p&gt;The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when `value` is a `%File.Stream{}`, because `filename` then defaults to `Path.basename(stream.path)` and POSIX filenames may legitimately contain `\r` and `\n`. RFC 7578 / WHATWG form-data requires percent-encoding `&amp;#34;`, CR, and LF in these fields; the fix adopts that behavior.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Construct a malicious `filename` such as `harmless.txt&amp;#34;\r\nX-Smuggled: marker\r\nContent-Disposition: form-data; name=&amp;#34;pwned`.
2. Call `Req.post!(url, form_multipart: [upload: {&amp;#34;benign body&amp;#34;, filename: &amp;lt;ma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: req&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Req&amp;#39;s multipart form encoder interpolates the per-part `name`, `filename`, and `content_type` directly into the part headers without escaping. An attacker who can influence any of those values can inject CRLF-separated header lines, smuggle additional form fields, or prepend a whole extra part into the request the victim service sends downstream.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`Req.Utils.encode_form_part/2` in `lib/req/utils.ex` builds the per-part header iodata by concatenating the three caller-supplied strings verbatim into `content-disposition: form-data; name=&amp;#34;&amp;lt;name&amp;gt;&amp;#34;; filename=&amp;#34;&amp;lt;filename&amp;gt;&amp;#34;` and `content-type: &amp;lt;content_type&amp;gt;`. There is no CRLF stripping, no quote escaping, and no validation. A value containing `&amp;#34;\r\n` closes the surrounding quoted value and starts a new header line; an additional `\r\n--&amp;lt;boundary&amp;gt;` terminates the current part and lets the attacker prepend a smuggled part.&lt;/p&gt;
&lt;p&gt;The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when `value` is a `%File.Stream{}`, because `filename` then defaults to `Path.basename(stream.path)` and POSIX filenames may legitimately contain `\r` and `\n`. RFC 7578 / WHATWG form-data requires percent-encoding `&amp;#34;`, CR, and LF in these fields; the fix adopts that behavior.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Construct a malicious `filename` such as `harmless.txt&amp;#34;\r\nX-Smuggled: marker\r\nContent-Disposition: form-data; name=&amp;#34;pwned`.
2. Call `Req.post!(url, form_multipart: [upload: {&amp;#34;benign body&amp;#34;, filename: &amp;lt;ma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-px9f-whj3-246m</guid>
    </item>
  </channel>
</rss>
