{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "High"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "summary",
        "text": "HPE Aruba Networking has released a software update for the HPE Aruba Networking Private 5G Core platform to address multiple security vulnerabilities.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "These vulnerabilities affect the following HPE Aruba Networking Private 5G Core software version unless specifically noted otherwise in the details section:  - HPE Aruba Networking Private 5G Core 1.26.1.0 and below.\n\n",
        "title": "Affected Products"
      },
      {
        "category": "general",
        "text": "Any other HPE Networking products not specifically listed above are not affected by these vulnerabilities.",
        "title": "Unaffected Products"
      },
      {
        "category": "other",
        "text": "HPE Aruba Networking recognizes that these CVEs have been widely discussed publicly. At this time, the company is not aware of any publicly available exploitation tools or techniques that specifically target the HPE Aruba Networking Private 5G Core Platform.",
        "title": "Exploitation and Public Discussion"
      },
      {
        "category": "general",
        "text": "Complete information on reporting security vulnerabilities in HPE Aruba Networking products and obtaining assistance with security incidents is available at:\nhttp://www.hpe.com/support/security-response-policy\n\nFor reporting NEW HPE Aruba Networking security issues, email can be sent to aruba-sirt@hpe.com. For sensitive information we encourage the use of PGP encryption. Our \npublic keys can be found at: \nhttps://www.hpe.com/info/psrt-pgp-key ",
        "title": "HPE Aruba Networking SIRT Security Procedures"
      },
      {
        "category": "legal_disclaimer",
        "text": "(c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date of the advisory, provided that the redistributed copies are complete and unmodified, including all data and version information.",
        "title": "Legal Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Email: hpe-networking-sirt@hpe.com - For further details please see https://www.hpe.com/support/security-response-policy",
      "issuing_authority": "HPE Aruba Networking's Security Incident Response Team (SIRT) is responsible for receiving, tracking, managing, and disclosing vulnerabilities in HPE Aruba Networking products. The HPE Aruba Networking SIRT actively works with industry, non-profit, government organizations, and the security community when vulnerabilities are reported.",
      "name": "HPE Networking",
      "namespace": "https://www.hpe.com/support/security-response-policy"
    },
    "references": [
      {
        "summary": "Original Advisory",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05077en_us&docLocale=en_US"
      },
      {
        "summary": "HPE Aruba Networking Security Advisory Archive",
        "url": "https://support.hpe.com/connect/s/securitybulletinlibrary/"
      },
      {
        "summary": "HPE Aruba Networking Product Security Incident Response Policy",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us"
      }
    ],
    "title": "HPE Athonet Core Multiple Vulnerabilities",
    "tracking": {
      "current_release_date": "2026-07-07T17:00:00.000Z",
      "generator": {
        "date": "2026-07-07T13:57:04.620Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.5"
        }
      },
      "id": "HPESBNW05077",
      "initial_release_date": "2026-07-07T17:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-07-07T17:00:00.000Z",
          "number": "1",
          "summary": "Initial Release"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.26.1.1",
                "product": {
                  "name": "Private 5G Core",
                  "product_id": "1.26.1.1"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=1.26.0.0|<=1.26.1.0 ",
                "product": {
                  "name": "Private 5G Core",
                  "product_id": ">=1.26.0.0|<=1.26.1.0 "
                }
              }
            ],
            "category": "product_name",
            "name": "Private 5G Core"
          }
        ],
        "category": "vendor",
        "name": "HPE Aruba Networking"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "gouldnicholas"
          ]
        }
      ],
      "cve": "CVE-2026-40912",
      "notes": [
        {
          "category": "details",
          "text": "There is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middleware when used in combination with ForwardAuth, BasicAuth, or DigestAuth. The middleware matches the regex against the decoded URL path but uses the resulting byte length to slice the percent-encoded raw path. When a dot (or multiple dots) appears in the prefix portion of the URL, the raw path after stripping becomes a dot-segment (e.g. /./admin/secret). ForwardAuth receives this dot-segment path in X-Forwarded-Uri, which does not match the protected path patterns and therefore allows the request through. The backend then  normalizes the dot-segment to the real path per RFC 3986 and serves the protected content. An unauthenticated attacker can exploit this against any backend that performs dot-segment normalization.    ",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-390",
          "title": "Internal Reference"
        }
      ],
      "product_status": {
        "fixed": [
          "1.26.1.1"
        ],
        "known_affected": [
          ">=1.26.0.0|<=1.26.1.0 "
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T17:00:00.000Z",
          "details": "HPE Aruba Networking recommends upgrading the software to the \nfollowing version:\n \n  - HPE Aruba Networking Private 5G Core 1.26.1.1 and above       \n\nNOTE: HPE Aruba Networking does not evaluate or patch HPE Aruba \nNetworking Private 5G Core Software versions that have \nreached their End of Support (EoS) milestone. \n  \nFor more information about HPE Aruba Networking Telco \nProduct Lifecycle and versioning policy, please visit: \nhttps://www.hpe.com/psnow/doc/4aa5-5978enw?jumpid=in_pdfviewer-psnow",
          "product_ids": [
            "1.26.1.1"
          ],
          "url": "https://www.hpe.com/psnow/doc/a00143052enw"
        },
        {
          "category": "workaround",
          "date": "2026-07-07T17:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these \nvulnerabilities, HPE Aruba Networking recommends that \nmanagement interfaces be restricted to a dedicated layer 2 \nsegment/VLAN and/or controlled by firewall policies at \nlayer 3 and above, along with accounting controls for \ntracking and logging user activities and resource usage. \nYou may contact HPE Services - HPE Aruba Networking for \nassistance if needed. For more information, please visit \nHPE Networking Support Portal at \nhttps://networkingsupport.hpe.com/home",
          "product_ids": [
            ">=1.26.0.0|<=1.26.1.0 "
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            ">=1.26.0.0|<=1.26.1.0 "
          ]
        }
      ],
      "title": "StripPrefixRegex auth bypass via Path/RawPath desync"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "PJUllrich"
          ]
        }
      ],
      "cve": "CVE-2026-39806",
      "notes": [
        {
          "category": "details",
          "text": "A worker-pinning denial of service in Bandit's HTTP/1 chunked transfer decoder. Any unauthenticated client that sends a Transfer-Encoding: chunked request whose body ends with a trailer field (RFC 9112 7.1.2 explicitly permits this) causes the connection's worker process to spin forever in an infinite recursion. A handful of concurrent connections are sufficient to exhaust the listener pool and render the server unresponsive to all further traffic.\n",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-392",
          "title": "Internal Reference"
        }
      ],
      "product_status": {
        "fixed": [
          "1.26.1.1"
        ],
        "known_affected": [
          ">=1.26.0.0|<=1.26.1.0 "
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T17:00:00.000Z",
          "details": "HPE Aruba Networking recommends upgrading the software to the \nfollowing version:\n \n  - HPE Aruba Networking Private 5G Core 1.26.1.1 and above       \n\nNOTE: HPE Aruba Networking does not evaluate or patch HPE Aruba \nNetworking Private 5G Core Software versions that have \nreached their End of Support (EoS) milestone. \n  \nFor more information about HPE Aruba Networking Telco \nProduct Lifecycle and versioning policy, please visit: \nhttps://www.hpe.com/psnow/doc/4aa5-5978enw?jumpid=in_pdfviewer-psnow",
          "product_ids": [
            "1.26.1.1"
          ],
          "url": "https://www.hpe.com/psnow/doc/a00143052enw"
        },
        {
          "category": "workaround",
          "date": "2026-07-07T17:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these \nvulnerabilities, HPE Aruba Networking recommends that \nmanagement interfaces be restricted to a dedicated layer 2 \nsegment/VLAN and/or controlled by firewall policies at \nlayer 3 and above, along with accounting controls for \ntracking and logging user activities and resource usage. \nYou may contact HPE Services - HPE Aruba Networking for \nassistance if needed. For more information, please visit \nHPE Networking Support Portal at \nhttps://networkingsupport.hpe.com/home",
          "product_ids": [
            ">=1.26.0.0|<=1.26.1.0 "
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            ">=1.26.0.0|<=1.26.1.0 "
          ]
        }
      ],
      "title": "Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "zzb1388"
          ]
        }
      ],
      "cve": "CVE-2026-39803",
      "notes": [
        {
          "category": "details",
          "text": "Bandit's HTTP/1 chunked-body reader silently drops the request size cap that the application configures (e.g. Plug.Parsers' default 8 MB length:) and buffers the entire body in memory before the application sees it. An unauthenticated attacker can crash any Bandit-fronted Phoenix/Plug app (BEAM OOM) with a single Transfer-Encoding: chunked request to any URL.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-393",
          "title": "Internal Reference"
        }
      ],
      "product_status": {
        "fixed": [
          "1.26.1.1"
        ],
        "known_affected": [
          ">=1.26.0.0|<=1.26.1.0 "
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T17:00:00.000Z",
          "details": "HPE Aruba Networking recommends upgrading the software to the \nfollowing version:\n \n  - HPE Aruba Networking Private 5G Core 1.26.1.1 and above       \n\nNOTE: HPE Aruba Networking does not evaluate or patch HPE Aruba \nNetworking Private 5G Core Software versions that have \nreached their End of Support (EoS) milestone. \n  \nFor more information about HPE Aruba Networking Telco \nProduct Lifecycle and versioning policy, please visit: \nhttps://www.hpe.com/psnow/doc/4aa5-5978enw?jumpid=in_pdfviewer-psnow",
          "product_ids": [
            "1.26.1.1"
          ],
          "url": "https://www.hpe.com/psnow/doc/a00143052enw"
        },
        {
          "category": "workaround",
          "date": "2026-07-07T17:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these \nvulnerabilities, HPE Aruba Networking recommends that \nmanagement interfaces be restricted to a dedicated layer 2 \nsegment/VLAN and/or controlled by firewall policies at \nlayer 3 and above, along with accounting controls for \ntracking and logging user activities and resource usage. \nYou may contact HPE Services - HPE Aruba Networking for \nassistance if needed. For more information, please visit \nHPE Networking Support Portal at \nhttps://networkingsupport.hpe.com/home",
          "product_ids": [
            ">=1.26.0.0|<=1.26.1.0 "
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "environmentalScore": 7.3,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.3,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            ">=1.26.0.0|<=1.26.1.0 "
          ]
        }
      ],
      "title": "Unauthenticated one-shot DoS via `Transfer-Encoding: chunked`"
    }
  ]
}