<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 18:53:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-369545</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-369545</link>
      <description>EUVD-2026-369545</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-369545</guid>
    </item>
    <item>
      <title>fkie_cve-2026-84997</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84997</link>
      <description>&lt;p&gt;react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete terminal-chunk trailer without CRLF left the buffer unchanged after strpos returned false, and exactly two non-CRLF bytes after a completed non-terminal chunk bypassed both the error and wait guards. The affected decoder processes request bodies for React\Http\HttpServer and response bodies for React\Http\Browser, allowing a malicious client to freeze a server or a malicious or compromised server to freeze a client. A reverse proxy that normalizes inbound requests may protect the server direction but does not protect outbound Browser requests. This issue is fixed in version 1.11.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete terminal-chunk trailer without CRLF left the buffer unchanged after strpos returned false, and exactly two non-CRLF bytes after a completed non-terminal chunk bypassed both the error and wait guards. The affected decoder processes request bodies for React\Http\HttpServer and response bodies for React\Http\Browser, allowing a malicious client to freeze a server or a malicious or compromised server to freeze a client. A reverse proxy that normalizes inbound requests may protect the server direction but does not protect outbound Browser requests. This issue is fixed in version 1.11.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-84997</guid>
    </item>
    <item>
      <title>GHSA-x424-64qh-5j54 — react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x424-64qh-5j54</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: react/http&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A malformed HTTP message using `Transfer-Encoding: chunked` can drive `React\Http\Io\ChunkedDecoder` into an infinite loop, pegging a CPU core and freezing the event loop. Because ReactPHP is single-threaded, one such message stalls the entire process for every client until it is killed.&lt;/p&gt;
&lt;p&gt;Both directions are affected. `ChunkedDecoder` decodes chunked **request** bodies for `React\Http\HttpServer` and chunked **response** bodies for `React\Http\Browser`, so a server can be attacked by a malicious client and a client can be attacked by a malicious or compromised server.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`ChunkedDecoder::handleData()` loops `while ($this-&amp;gt;buffer !== &amp;#39;&amp;#39;)` and relies on the buffer shrinking each iteration. Two states leave the buffer unchanged while the loop condition stays true.&lt;/p&gt;
&lt;p&gt;**Terminal-chunk trailer.** After the terminating `0` chunk, any remaining buffer is treated as trailer data to skip:&lt;/p&gt;
&lt;p&gt;```php
} elseif ($this-&amp;gt;chunkSize === 0) {
    $this-&amp;gt;buffer = (string)\substr($this-&amp;gt;buffer, $positionCrlf);
}
```&lt;/p&gt;
&lt;p&gt;When the trailer holds no CRLF yet, `strpos()` returns `false`, PHP coerces that to `0` in `substr()`, and the buffer is never advanced. Neither the error guard (which requires a non-zero chunk size) nor the wait guard (which requires fewer than two bytes remaining) can fire, so the loop re-enters with identical state.&lt;/p&gt;
&lt;p&gt;**Off-by-one after a completed chunk.** Once a non-terminal chunk has been fully transferred, the &amp;#34;chunk does not end with a CRLF&amp;#34; error guard r…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: react/http&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A malformed HTTP message using `Transfer-Encoding: chunked` can drive `React\Http\Io\ChunkedDecoder` into an infinite loop, pegging a CPU core and freezing the event loop. Because ReactPHP is single-threaded, one such message stalls the entire process for every client until it is killed.&lt;/p&gt;
&lt;p&gt;Both directions are affected. `ChunkedDecoder` decodes chunked **request** bodies for `React\Http\HttpServer` and chunked **response** bodies for `React\Http\Browser`, so a server can be attacked by a malicious client and a client can be attacked by a malicious or compromised server.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`ChunkedDecoder::handleData()` loops `while ($this-&amp;gt;buffer !== &amp;#39;&amp;#39;)` and relies on the buffer shrinking each iteration. Two states leave the buffer unchanged while the loop condition stays true.&lt;/p&gt;
&lt;p&gt;**Terminal-chunk trailer.** After the terminating `0` chunk, any remaining buffer is treated as trailer data to skip:&lt;/p&gt;
&lt;p&gt;```php
} elseif ($this-&amp;gt;chunkSize === 0) {
    $this-&amp;gt;buffer = (string)\substr($this-&amp;gt;buffer, $positionCrlf);
}
```&lt;/p&gt;
&lt;p&gt;When the trailer holds no CRLF yet, `strpos()` returns `false`, PHP coerces that to `0` in `substr()`, and the buffer is never advanced. Neither the error guard (which requires a non-zero chunk size) nor the wait guard (which requires fewer than two bytes remaining) can fire, so the loop re-enters with identical state.&lt;/p&gt;
&lt;p&gt;**Off-by-one after a completed chunk.** Once a non-terminal chunk has been fully transferred, the &amp;#34;chunk does not end with a CRLF&amp;#34; error guard r…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x424-64qh-5j54</guid>
    </item>
  </channel>
</rss>
