<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T20:09:08.788044+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-01641</id>
    <title>bdu:2025-01641</title>
    <updated>2026-10-06T20:09:08.870539+00:00</updated>
    <content>bdu:2025-01641</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-01641"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-vite-cve-2025-24010</id>
    <title>BREW-vite-CVE-2025-24010 — Websites were able to send any requests to the development server and read the response in vite</title>
    <updated>2026-10-06T20:09:08.870579+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: vite</p>
<p>### Summary
Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections.</p>
<p>&gt; [!WARNING]
&gt; This vulnerability even applies to users that only run the Vite dev server on the local machine and does not expose the dev server to the network.</p>
<p>### Upgrade Path
Users that does not match either of the following conditions should be able to upgrade to a newer version of Vite that fixes the vulnerability without any additional configuration.</p>
<p>- Using the backend integration feature
- Using a reverse proxy in front of Vite
- Accessing the development server via a domain other than `localhost` or `*.localhost`
- Using a plugin / framework that connects to the WebSocket server on their own from the browser</p>
<p>#### Using the backend integration feature
If you are using the backend integration feature and not setting [`server.origin`](https://vite.dev/config/server-options.html#server-origin), you need to add the origin of the backend server to the [`server.cors.origin`](https://github.com/expressjs/cors#configuration-options) option. Make sure to set a specific origin rather than `*`, otherwise any origin can access your development server.</p>
<p>#### Using a reverse proxy in front of Vite
If you are using a reverse proxy in front of Vite and sending requests to Vite with a hostname other than `localhost` or `*.localhost`, you need to add the hostname to the new [`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-vite-cve-2025-24010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-211156</id>
    <title>EUVD-2026-211156</title>
    <updated>2026-10-06T20:09:08.870658+00:00</updated>
    <content>EUVD-2026-211156</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-211156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-24010</id>
    <title>fkie_cve-2025-24010</title>
    <updated>2026-10-06T20:09:08.870672+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-24010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vg6x-rcgg-rjx6</id>
    <title>GHSA-vg6x-rcgg-rjx6 — Websites were able to send any requests to the development server and read the response in vite</title>
    <updated>2026-10-06T20:09:08.870703+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vite</p>
<p>### Summary
Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections.</p>
<p>&gt; [!WARNING]
&gt; This vulnerability even applies to users that only run the Vite dev server on the local machine and does not expose the dev server to the network.</p>
<p>### Upgrade Path
Users that does not match either of the following conditions should be able to upgrade to a newer version of Vite that fixes the vulnerability without any additional configuration.</p>
<p>- Using the backend integration feature
- Using a reverse proxy in front of Vite
- Accessing the development server via a domain other than `localhost` or `*.localhost`
- Using a plugin / framework that connects to the WebSocket server on their own from the browser</p>
<p>#### Using the backend integration feature
If you are using the backend integration feature and not setting [`server.origin`](https://vite.dev/config/server-options.html#server-origin), you need to add the origin of the backend server to the [`server.cors.origin`](https://github.com/expressjs/cors#configuration-options) option. Make sure to set a specific origin rather than `*`, otherwise any origin can access your development server.</p>
<p>#### Using a reverse proxy in front of Vite
If you are using a reverse proxy in front of Vite and sending requests to Vite with a hostname other than `localhost` or `*.localhost`, you need to add the hostname to the new [`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vg6x-rcgg-rjx6"/>
  </entry>
</feed>
