<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:37:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335484</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335484</link>
      <description>EUVD-2026-335484</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335484</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50188</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50188</link>
      <description>&lt;p&gt;Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data in the headers option could allow newline characters in a header value to inject a separate unintended request header to the remote service. This issue is fixed in versions 4.9.4 and 5.4.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data in the headers option could allow newline characters in a header value to inject a separate unintended request header to the remote service. This issue is fixed in versions 4.9.4 and 5.4.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50188</guid>
    </item>
    <item>
      <title>GHSA-4v4h-m2qq-ppgw — Kirby: Request header injection in `Http\Remote`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4v4h-m2qq-ppgw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getkirby/cms&lt;/p&gt;
&lt;p&gt;### TL;DR&lt;/p&gt;
&lt;p&gt;This vulnerability affects Kirby sites and plugins that use the `Kirby\Http\Remote` class (including `Remote::request()`, `Remote::get()`, `Remote::post()`, and similar helpers) to send outgoing HTTP requests and that pass untrusted, user-controlled data into the `headers` option of such a request.&lt;/p&gt;
&lt;p&gt;By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set.&lt;/p&gt;
&lt;p&gt;A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are *not* affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to.&lt;/p&gt;
&lt;p&gt;In Kirby&amp;#39;s default configuration, the `Remote` class is not exposed to untrusted input, so a default installation is *not* affected. The vulnerability becomes relevant for custom code, plugins, or integrations that build request headers from user input.&lt;/p&gt;
&lt;p&gt;----&lt;/p&gt;
&lt;p&gt;### Introduction&lt;/p&gt;
&lt;p&gt;HTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters (`\r\n`). If untrusted data containing these characters is placed into a header value without sanitization, an attacker can terminate the intended header early and append headers o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getkirby/cms&lt;/p&gt;
&lt;p&gt;### TL;DR&lt;/p&gt;
&lt;p&gt;This vulnerability affects Kirby sites and plugins that use the `Kirby\Http\Remote` class (including `Remote::request()`, `Remote::get()`, `Remote::post()`, and similar helpers) to send outgoing HTTP requests and that pass untrusted, user-controlled data into the `headers` option of such a request.&lt;/p&gt;
&lt;p&gt;By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set.&lt;/p&gt;
&lt;p&gt;A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are *not* affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to.&lt;/p&gt;
&lt;p&gt;In Kirby&amp;#39;s default configuration, the `Remote` class is not exposed to untrusted input, so a default installation is *not* affected. The vulnerability becomes relevant for custom code, plugins, or integrations that build request headers from user input.&lt;/p&gt;
&lt;p&gt;----&lt;/p&gt;
&lt;p&gt;### Introduction&lt;/p&gt;
&lt;p&gt;HTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters (`\r\n`). If untrusted data containing these characters is placed into a header value without sanitization, an attacker can terminate the intended header early and append headers o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4v4h-m2qq-ppgw</guid>
    </item>
  </channel>
</rss>
