<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T20:46:11.658612+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1127</id>
    <title>certfr-2025-avi-1127 — De multiples vulnérabilités ont été découvertes dans Centreon Web. Elles permettent à un attaquant de provoquer un prob…</title>
    <updated>2026-10-04T20:46:11.752552+00:00</updated>
    <content>certfr-2025-avi-1127</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-235150</id>
    <title>EUVD-2026-235150</title>
    <updated>2026-10-04T20:46:11.752592+00:00</updated>
    <content>EUVD-2026-235150</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-235150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-43865</id>
    <title>fkie_cve-2025-43865</title>
    <updated>2026-10-04T20:46:11.752607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. This issue has been patched in version 7.5.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-43865"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cpj6-fhp6-mr6j</id>
    <title>GHSA-cpj6-fhp6-mr6j — React Router allows pre-render data spoofing on React-Router framework mode</title>
    <updated>2026-10-04T20:46:11.752638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: react-router</p>
<p>## Summary
After some research, it turns out that it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. Latest versions are impacted.</p>
<p>## Details
The vulnerable header is `X-React-Router-Prerender-Data`, a specific JSON object must be passed to it in order for the spoofing to be successful as we will see shortly. Here is [the vulnerable code](https://github.com/remix-run/react-router/blob/e6c53a0130559b4a9bd47f9cf76ea5b08a69868a/packages/react-router/lib/server-runtime/routes.ts#L87) :</p>
<p>&lt;img width="776" alt="Capture d’écran 2025-04-07 à 05 36 58" src="https://github.com/user-attachments/assets/c95b0b33-15ce-4d30-9f5e-b10525dd6ab4" /&gt;</p>
<p>To use the header, React-router must be used in Framework mode, and for the attack to be possible the target page must use a loader.</p>
<p>## Steps to reproduce 
Versions used for our PoC: 
- "@react-router/node": "^7.5.0",
- "@react-router/serve": "^7.5.0",
- "react": "^19.0.0"
- "react-dom": "^19.0.0"
- "react-router": "^7.5.0"</p>
<p>1. Install React-Router with its default configuration in Framework mode (https://reactrouter.com/start/framework/installation)
2. Add a simple page using a loader (example: `routes/ssr`)
3. Access your page (*which uses the loader*) by suffixing it with `.data`. In our case the page is called `/ssr`:</p>
<p>![image](https://github.com/user-attachments/assets/d7d04e86-c549-4f4a-9200-2d1b6ac96aa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cpj6-fhp6-mr6j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:13904</id>
    <title>RHSA-2025:13904 — Red Hat Security Advisory: RHOAI 2.23.0 - Red Hat OpenShift AI</title>
    <updated>2026-10-04T20:46:11.752735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>react-router: React Router allows pre-render data spoofing on React-Router framework mode</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:13904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1435</id>
    <title>WID-SEC-W-2025-1435 — IBM Storage Scale: Mehrere Schwachstellen</title>
    <updated>2026-10-04T20:46:11.752757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM Storage Scale ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1435"/>
  </entry>
</feed>
