<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:45:42.671622+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-66495</id>
    <title>cnvd-2022-66495</title>
    <updated>2026-10-03T19:45:42.807765+00:00</updated>
    <content>cnvd-2022-66495</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-66495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232698</id>
    <title>EUVD-2026-232698</title>
    <updated>2026-10-03T19:45:42.807814+00:00</updated>
    <content>EUVD-2026-232698</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31019</id>
    <title>fkie_cve-2022-31019</title>
    <updated>2026-10-03T19:45:42.807832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vapor is a server-side Swift HTTP web framework. When using automatic content decoding an attacker can craft a request body that can make the server crash with the following request: `curl -d "array[_0][0][array][_0][0][array]$(for f in $(seq 1100); do echo -n '[_0][0][array]'; done)[string][_0]=hello%20world" http://localhost:8080/foo`. The issue is unbounded, attacker controlled stack growth which will at some point lead to a stack overflow and a process crash. This issue has been fixed in version 4.61.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-31019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qvxg-wjxc-r4gg</id>
    <title>GHSA-qvxg-wjxc-r4gg — Vapor vulnerable to denial of service in URLEncodedFormDecoder</title>
    <updated>2026-10-03T19:45:42.807870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> SwiftURL: github.com/vapor/vapor</p>
<p>Vapor is an HTTP web framework for Swift. Vapor versions earlier than 4.61.1 are vulnerable to a denial of service in the URLEncodedFormDecoder.</p>
<p>### Impact
When using automatic content decoding, e.g.</p>
<p>```swift
app.post("foo") { request -&gt; String in
  let foo = try request.content.decode(Foo.self)
  return "\(foo)"
}
```</p>
<p>An attacker can craft a request body that can make the server crash with the following request:</p>
<p>```
curl -d "array[_0][0][array][_0][0][array]$(for f in $(seq 1100); do echo -n '[_0][0][array]'; done)[string][_0]=hello%20world" http://localhost:8080/foo
```</p>
<p>The issue is unbounded, attacker controlled stack growth which will at some point lead to a stack overflow.</p>
<p>### Patches
Fixed in 4.61.1</p>
<p>### Workarounds
If you don't need to decode Form URL Encoded data, you can disable the `ContentConfiguration` so it won't be used. E.g. in **configure.swift**</p>
<p>```swift
var contentConfig = ContentConfiguration()
contentConfig.use(encoder: JSONEncoder.custom(dates: .iso8601), for: .json)
contentConfig.use(decoder: JSONDecoder.custom(dates: .iso8601), for: .json)
contentConfig.use(encoder: JSONEncoder.custom(dates: .iso8601), for: .jsonAPI)
contentConfig.use(decoder: JSONDecoder.custom(dates: .iso8601), for: .jsonAPI)
ContentConfiguration.global = contentConfig
```</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in [the Vapor repo](https://github.com/vapor/vapor)
* Ask in [Vapor Discord](http://vapor.team)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qvxg-wjxc-r4gg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-31019</id>
    <title>gsd-2022-31019</title>
    <updated>2026-10-03T19:45:42.807918+00:00</updated>
    <content>gsd-2022-31019</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-31019"/>
  </entry>
</feed>
