<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-26T16:10:02Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by X41 D-Sec GmbH</title>
  <author>
    <name>X41 D-Sec GmbH</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1a7knlj2daku4ka2rtfs2hlj8tp42yrgg0gp9d3v5ftngwkma03zqvnguxz.rss" />
  <link href="https://nostr.ae/npub1a7knlj2daku4ka2rtfs2hlj8tp42yrgg0gp9d3v5ftngwkma03zqvnguxz" />
  <id>https://nostr.ae/npub1a7knlj2daku4ka2rtfs2hlj8tp42yrgg0gp9d3v5ftngwkma03zqvnguxz</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/111/773/270/792/541/198/original/c978edfd2c13fd08.png</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/111/773/270/792/541/198/original/c978edfd2c13fd08.png</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsp3z6v7dmfhv2r7kpfpqunmzlf3ffqd9qr96zgu7gsl4dsamkktfgzyrh6607ffhkmjkm4gddxp2l7gavx4gsdppaqy4k9j39wdp6m047ygdk0pws</id>
    
      <title type="html">There&amp;#39;s an update for the Starlette issue: We&amp;#39;ve scanned ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp3z6v7dmfhv2r7kpfpqunmzlf3ffqd9qr96zgu7gsl4dsamkktfgzyrh6607ffhkmjkm4gddxp2l7gavx4gsdppaqy4k9j39wdp6m047ygdk0pws" />
    <content type="html">
      There&amp;#39;s an update for the Starlette issue: We&amp;#39;ve scanned thousands of hosts for CVE-2026-48710 and found something important: Being behind a proxy or CloudFlare isn&amp;#39;t always a protection unlike previously stated!&lt;br/&gt;When a reverse proxy or CDN (including Cloudflare) sits in front of the target and rejects malformed Host headers, the X-Forwarded-Host header can sometimes be used to bypass the protection! If the backend middleware reads X-Forwarded-Host and updates the ASGI scope, the malicious value can reach the ASGI and Starlette. #badhost
    </content>
    <updated>2026-05-28T07:30:41Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsy5z9qf8gt24kwp8nvanq9xy6r7wcd6afmc8q477d4r5uf6dee9hszyrh6607ffhkmjkm4gddxp2l7gavx4gsdppaqy4k9j39wdp6m047ygc966vz</id>
    
      <title type="html">After auditing the @npub1xh7…v9hj client applications in 2024, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsy5z9qf8gt24kwp8nvanq9xy6r7wcd6afmc8q477d4r5uf6dee9hszyrh6607ffhkmjkm4gddxp2l7gavx4gsdppaqy4k9j39wdp6m047ygc966vz" />
    <content type="html">
      After auditing the &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1xh7cv0xku4rqrp0yay046zw2y0wwl0mguzguq49zv2lye4a69zrs45v9hj&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Mullvad VPN&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1xh7…v9hj&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; client applications in 2024, we have recently audited Mullvad VPN&amp;#39;s API.&lt;br/&gt;The API is used by clients, partners, and internal services to manage user accounts and parts of the VPN infrastructure.&lt;br/&gt;Five issues were identified, of which only one had a very limited impact on users of the service.&lt;br/&gt;&lt;br/&gt;The technical details may be found in our report. &lt;a href=&#34;https://www.x41-dsec.de/security/research/news/2026/01/20/mullvad/&#34;&gt;https://www.x41-dsec.de/security/research/news/2026/01/20/mullvad/&lt;/a&gt;
    </content>
    <updated>2026-01-21T16:22:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst7xhzxpcgudtj8fnx9gexndug54avjh897w2z2znrvd30un8uaxgzyrh6607ffhkmjkm4gddxp2l7gavx4gsdppaqy4k9j39wdp6m047yg7lncnw</id>
    
      <title type="html">X41 performed an audit of Hickory DNS which is an open source ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst7xhzxpcgudtj8fnx9gexndug54avjh897w2z2znrvd30un8uaxgzyrh6607ffhkmjkm4gddxp2l7gavx4gsdppaqy4k9j39wdp6m047yg7lncnw" />
    <content type="html">
      X41 performed an audit of Hickory DNS which is an open source Rust based DNS client, server, and resolver. We were sponsored by the great folks at &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1c8cuu3n4u3xdhz57fh5fexym7xs48wncp7drk0dvxzcv87t4dtysz6lkhj&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;OSTIF&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1c8c…lkhj&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; and supported by &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1jsv8a3t53jzyun354qpltd6klwrlstltdatl36qng3qlzj9ltehsgrg5xu&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Prossimo&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1jsv…g5xu&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;Our full report can be downloaded here: &lt;a href=&#34;https://x41-dsec.de/security/research/job/news/2025/03/10/hickory-review-2025/&#34;&gt;https://x41-dsec.de/security/research/job/news/2025/03/10/hickory-review-2025/&lt;/a&gt;
    </content>
    <updated>2025-03-10T12:35:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsw9jwwlhmzqasymyhpartrsjznjkw20j5vvsvp6dkyaqxlctjxjrczyrh6607ffhkmjkm4gddxp2l7gavx4gsdppaqy4k9j39wdp6m047yggu6l49</id>
    
      <title type="html">X41 Reviewed Mullvad VPN ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsw9jwwlhmzqasymyhpartrsjznjkw20j5vvsvp6dkyaqxlctjxjrczyrh6607ffhkmjkm4gddxp2l7gavx4gsdppaqy4k9j39wdp6m047yggu6l49" />
    <content type="html">
      X41 Reviewed Mullvad VPN&lt;br/&gt;&lt;a href=&#34;https://x41-dsec.de/news/2024/12/11/mullvad/&#34;&gt;https://x41-dsec.de/news/2024/12/11/mullvad/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Many thanks to the &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1xh7cv0xku4rqrp0yay046zw2y0wwl0mguzguq49zv2lye4a69zrs45v9hj&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Mullvad VPN&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1xh7…v9hj&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; team for the professional and good interaction during this audit!
    </content>
    <updated>2024-12-11T16:39:26Z</updated>
  </entry>

</feed>