<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:04:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343829</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343829</link>
      <description>EUVD-2026-343829</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343829</guid>
    </item>
    <item>
      <title>fkie_cve-2026-67339</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67339</link>
      <description>&lt;p&gt;guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-67339</guid>
    </item>
    <item>
      <title>GHSA-94pj-82f3-465w — Guzzle: Proxy-Authorization headers can be sent to origin servers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-94pj-82f3-465w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: guzzlehttp/guzzle&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In affected versions, the built-in cURL handlers (`CurlHandler` and `CurlMultiHandler`) put every first-class request header in cURL&amp;#39;s origin header list (`CURLOPT_HTTPHEADER`). These handlers are the default when the PHP cURL extension is available. They move `Proxy-Authorization` to the proxy-only list (`CURLOPT_PROXYHEADER`) only when Guzzle predicts an HTTP or HTTPS proxy. A &amp;#34;first-class&amp;#34; header is part of the normal request message and can be set on a PSR-7 request, through client `headers` defaults, the `headers` request option, or middleware. It does not include a literal line supplied through raw `CURLOPT_HTTPHEADER`, `CURLOPT_PROXYHEADER`, or `stream_context.http.header` controls.&lt;/p&gt;
&lt;p&gt;Because that migration follows Guzzle&amp;#39;s prediction rather than the route libcurl actually takes, the credential stays in the origin list and is sent to the origin server when a request is:&lt;/p&gt;
&lt;p&gt;- direct, including `proxy` set to `&amp;#39;&amp;#39;` to disable proxying.
- bypassed by a `no`, `no_proxy`, or `NO_PROXY` match.
- sent through a SOCKS proxy, which does not use the HTTP proxy header channel.
- redirected from a safely proxied hop into any of those routes: redirect middleware re-evaluates the proxy per hop but, unlike `Authorization` and `Cookie`, does not strip `Proxy-Authorization` cross-origin.&lt;/p&gt;
&lt;p&gt;On installations whose libcurl is older than 7.37.0, or whose PHP cURL extension lacks `CURLOPT_PROXYHEADER`, `CURLOPT_HEADEROPT`, and `CURLHEADER_SEPARATE`, no proxy-only channel is availabl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: guzzlehttp/guzzle&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In affected versions, the built-in cURL handlers (`CurlHandler` and `CurlMultiHandler`) put every first-class request header in cURL&amp;#39;s origin header list (`CURLOPT_HTTPHEADER`). These handlers are the default when the PHP cURL extension is available. They move `Proxy-Authorization` to the proxy-only list (`CURLOPT_PROXYHEADER`) only when Guzzle predicts an HTTP or HTTPS proxy. A &amp;#34;first-class&amp;#34; header is part of the normal request message and can be set on a PSR-7 request, through client `headers` defaults, the `headers` request option, or middleware. It does not include a literal line supplied through raw `CURLOPT_HTTPHEADER`, `CURLOPT_PROXYHEADER`, or `stream_context.http.header` controls.&lt;/p&gt;
&lt;p&gt;Because that migration follows Guzzle&amp;#39;s prediction rather than the route libcurl actually takes, the credential stays in the origin list and is sent to the origin server when a request is:&lt;/p&gt;
&lt;p&gt;- direct, including `proxy` set to `&amp;#39;&amp;#39;` to disable proxying.
- bypassed by a `no`, `no_proxy`, or `NO_PROXY` match.
- sent through a SOCKS proxy, which does not use the HTTP proxy header channel.
- redirected from a safely proxied hop into any of those routes: redirect middleware re-evaluates the proxy per hop but, unlike `Authorization` and `Cookie`, does not strip `Proxy-Authorization` cross-origin.&lt;/p&gt;
&lt;p&gt;On installations whose libcurl is older than 7.37.0, or whose PHP cURL extension lacks `CURLOPT_PROXYHEADER`, `CURLOPT_HEADEROPT`, and `CURLHEADER_SEPARATE`, no proxy-only channel is availabl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-94pj-82f3-465w</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-67339</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67339</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: guzzle, Ubuntu:26.04:LTS: guzzle&lt;/p&gt;
&lt;p&gt;guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: guzzle, Ubuntu:26.04:LTS: guzzle&lt;/p&gt;
&lt;p&gt;guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67339</guid>
    </item>
  </channel>
</rss>
