freenode

← digests

HTTP signature keys and Cudy router CVEs

Radar2026-08-20

The IETF HTTP Working Group opened a call for adoption on a draft for signature key handling, while a single disclosure reported command injection flaws in Cudy router firmware. Both items remain technical and narrowly scoped.

HTTP WG call for signature key draft adoption

The IETF HTTP Working Group has opened a call for adoption of draft-hardt-httpbis-signature-key-08, which adds key distribution and negotiation headers for RFC 9421 signatures. The call runs until 2026-09-07 and has produced technical objections on complexity across 17 messages from 8 participants. Developers working with HTTP message signatures should weigh the added mechanisms before the deadline.

Cudy WR3000 hard-coded JWT yields root injection

A full-disclosure post reports two CVEs in the closed firmware of the Cudy WR3000 router, where a hard-coded JWT secret leads to root command injection. The single-message notice provides the only public detail so far. Operators of similar embedded devices have reason to treat static credentials as a practical risk.