<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:34:32.232292+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-242064</id>
    <title>EUVD-2026-242064</title>
    <updated>2026-10-03T12:34:32.292728+00:00</updated>
    <content>EUVD-2026-242064</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-242064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23340</id>
    <title>fkie_cve-2024-23340</title>
    <updated>2026-10-03T12:34:32.292769+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>@hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request object with `url` behavior that is unexpected. In the standard API, if the URL contains `..`, here called "double dots", the URL string returned by Request will be in the resolved path. However, the `url` in @hono/node-server's Request as does not resolve double dots, so `http://localhost/static/.. /foo.txt` is returned. This causes vulnerabilities when using `serveStatic`. Modern web browsers and a latest `curl` command resolve double dots on the client side, so this issue doesn't affect those using either of those tools. However, problems may occur if accessed by a client that does not resolve them. Version 1.4.1 includes the change to fix this issue. As a workaround, don't use `serveStatic`.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-23340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rjq5-w47x-x359</id>
    <title>GHSA-rjq5-w47x-x359 — @hono/node-server cannot handle "double dots" in URL</title>
    <updated>2026-10-03T12:34:32.292809+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @hono/node-server</p>
<p>### Impact</p>
<p>Since v1.3.0, we use our own Request object. This is great, but the `url` behavior is unexpected.</p>
<p>In the standard API, if the URL contains `..`, here called "double dots", the URL string returned by Request will be in the resolved path.</p>
<p>```ts
const req = new Request('http://localhost/static/../foo.txt') // Web-standards
console.log(req.url) // http://localhost/foo.txt
```</p>
<p>However, the `url` in our Request does not resolve double dots, so `http://localhost/static/.. /foo.txt` is returned.</p>
<p>```ts
const req = new Request('http://localhost/static/../foo.txt')
console.log(req.url) // http://localhost/static/../foo.txt
```</p>
<p>It will pass unresolved paths to the web application. This causes vulnerabilities like #123 when using `serveStatic`.</p>
<p>Note: Modern web browsers and a latest `curl` command resolve double dots on the client side, so it does not affect you if the user uses them. However, problems may occur if accessed by a client that does not resolve them.</p>
<p>### Patches</p>
<p>"v1.4.1" includes the change to fix this issue.</p>
<p>### Workarounds</p>
<p>Don't use `serveStatic`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rjq5-w47x-x359"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-23340</id>
    <title>gsd-2024-23340</title>
    <updated>2026-10-03T12:34:32.292852+00:00</updated>
    <content>gsd-2024-23340</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-23340"/>
  </entry>
</feed>
