<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T21:15:07.794937+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232675</id>
    <title>EUVD-2026-232675</title>
    <updated>2026-10-09T21:15:07.797795+00:00</updated>
    <content>EUVD-2026-232675</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232675"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31140</id>
    <title>fkie_cve-2022-31140</title>
    <updated>2026-10-09T21:15:07.797826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12.0, Valinor can use `Throwable#getMessage()` when it should not have permission to do so. This is a problem with cases such as an SQL exception showing an SQL snippet, a database connection exception showing database IP address/username/password, or a timeout detail / out of memory detail. Attackers could use this information for potential data exfiltration, denial of service attacks, enumeration attacks, etc. Version 0.12.0 contains a patch for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-31140"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5pgm-3j3g-2rc7</id>
    <title>GHSA-5pgm-3j3g-2rc7 — Valinor error messages leading to potential data exfiltration before v0.12.0</title>
    <updated>2026-10-09T21:15:07.797860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: cuyz/valinor</p>
<p>```php
&lt;?php</p>
<p>namespace My\App;</p>
<p>use CuyZ\Valinor\Mapper\MappingError;
use CuyZ\Valinor\Mapper\Tree\Node;
use CuyZ\Valinor\Mapper\Tree\NodeTraverser;
use CuyZ\Valinor\MapperBuilder;</p>
<p>require_once __DIR__ . '/Valinor/vendor/autoload.php';</p>
<p>final class Money
{
    private function __construct(public readonly string $amount)
    {
    }</p>
<p>public static function fromString(string $money): self
    {
        if (1 !== \preg_match('/^\d+ [A-Z]{3}$/', $money)) {
            throw new \InvalidArgumentException(\sprintf('Given "%s" is not a recognized monetary amount', $money));
        }
        
        return new self($money);
    }
}</p>
<p>class Foo
{
    public function __construct(
        private readonly Money $a,
        private readonly Money $b,
        private readonly Money $c,
    ) {}
}</p>
<p>$mapper = (new MapperBuilder())
    -&gt;registerConstructor([Money::class, 'fromString'])
    -&gt;mapper();</p>
<p>try {
    var_dump($mapper-&gt;map(Foo::class, [
        'a' =&gt; 'HAHA',
        'b' =&gt; '100 EUR',
        'c' =&gt; 'USD 100'
    ]));
} catch (MappingError $e) {
    $messages = (new NodeTraverser(function (Node $node) {
        foreach ($node-&gt;messages() as $message) {
            var_dump([
                '$message',
                $message-&gt;path(),
                $message-&gt;body()
            ]);
        }
        return '';
    }))-&gt;traverse($e-&gt;node());</p>
<p>iterator_to_array($messages);
}
```</p>
<p>Now, this is quite innocent: it produces following output:</p>
<p>```
❯ php value-object-conver…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5pgm-3j3g-2rc7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-31140</id>
    <title>gsd-2022-31140</title>
    <updated>2026-10-09T21:15:07.797914+00:00</updated>
    <content>gsd-2022-31140</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-31140"/>
  </entry>
</feed>
