<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T03:56:56.200832+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-240966</id>
    <title>EUVD-2026-240966</title>
    <updated>2026-10-05T03:56:56.203556+00:00</updated>
    <content>EUVD-2026-240966</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-240966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48075</id>
    <title>fkie_cve-2025-48075</title>
    <updated>2026-10-05T03:56:56.203589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, but when idx is negative, it causes a panic instead of returning an error stating it cannot process the data. Since this data is user-provided, this could lead to denial of service for anyone relying on this `fiber.Ctx.BodyParser`  functionality. Version 2.52.7 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-48075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hg3g-gphw-5hhm</id>
    <title>GHSA-hg3g-gphw-5hhm — Fiber panics when fiber.Ctx.BodyParser parses invalid range index</title>
    <updated>2026-10-05T03:56:56.203621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gofiber/fiber/v2</p>
<p>### Summary
When using the `fiber.Ctx.BodyParser` to parse into a struct with range values, a panic occurs when trying to parse a negative range index</p>
<p>### Details
`fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, however when idx is negative, it causes a panic instead of returning an error stating it cannot process the data.</p>
<p>Since this data is user-provided, this could lead to denial of service for anyone relying on this `fiber.Ctx.BodyParser`  functionality</p>
<p>### Reproducing
Take a simple GoFiberV2 server which returns a JSON encoded version of the FormData
```go
package main</p>
<p>import (
	"encoding/json"
	"fmt"
	"net/http"</p>
<p>"github.com/gofiber/fiber/v2"
)</p>
<p>type RequestBody struct {
	NestedContent []*struct {
		Value string `form:"value"`
	} `form:"nested-content"`
}</p>
<p>func main() {
	app := fiber.New()</p>
<p>app.Post("/", func(c *fiber.Ctx) error {
		formData := RequestBody{}
		if err := c.BodyParser(&amp;formData); err != nil {
			fmt.Println(err)
			return c.SendStatus(http.StatusUnprocessableEntity)
		}
                c.Set("Content-Type", "application/json")
                s, _ := json.Marshal(formData)
                return c.SendString(string(s))
	})</p>
<p>fmt.Println(app.Listen(":3000"))
}</p>
<p>```</p>
<p>**Correct Behaviour**
Send a valid request such as:
```bash
curl --location 'localhost:3000' \
--form 'nested-content[0].value="Foo"' \
--form 'nested-content[1].value="Bar"'
```
You recieve valid JSON
```json
{"NestedContent":[{"Value":"Foo"},{"…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hg3g-gphw-5hhm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15179-1</id>
    <title>openSUSE-SU-2025:15179-1 — govulncheck-vulndb-0.0.20250527T204717-1.1 on GA media</title>
    <updated>2026-10-05T03:56:56.203672+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250527T204717-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15179-1"/>
  </entry>
</feed>
