<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:33:58.215883+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</id>
    <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T00:33:58.285025+00:00</updated>
    <content>certfr-2025-avi-0969</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-249273</id>
    <title>EUVD-2026-249273</title>
    <updated>2026-10-03T00:33:58.285067+00:00</updated>
    <content>EUVD-2026-249273</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-249273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54801</id>
    <title>fkie_cve-2025-54801</title>
    <updated>2026-10-03T00:33:58.285083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. The root cause is that the decoder attempts to allocate a slice of length idx + 1 without validating whether the index is within a safe or reasonable range. If the idx is excessively large, this leads to an integer overflow or memory exhaustion, causing a panic or crash. This is fixed in version 2.52.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-54801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qx2q-88mx-vhg7</id>
    <title>GHSA-qx2q-88mx-vhg7 — Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder</title>
    <updated>2026-10-03T00:33:58.285118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gofiber/fiber/v2</p>
<p>### Description</p>
<p>When using Fiber's `Ctx.BodyParser` to parse form data containing a large numeric key that represents a slice index (e.g., `test.18446744073704`), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder.</p>
<p>The root cause is that the decoder attempts to allocate a slice of length `idx + 1` without validating whether the index is within a safe or reasonable range. If `idx` is excessively large, this leads to an integer overflow or memory exhaustion, causing a panic or crash.</p>
<p>### Steps to Reproduce</p>
<p>Create a POST request handler that accepts `x-www-form-urlencoded` data</p>
<p>```go
package main</p>
<p>import (
	"fmt"
	"net/http"</p>
<p>"github.com/gofiber/fiber/v2"
)</p>
<p>type RequestBody struct {
	NestedContent []*struct{} `form:"test"`
}</p>
<p>func main() {
	app := fiber.New()</p>
<p>app.Post("/", func(c *fiber.Ctx) error {
		formData := RequestBody{}
		if err := c.BodyParser(&amp;formData); err != nil {
			fmt.Println(err)
			return c.SendStatus(http.StatusUnprocessableEntity)
		}
		return nil
	})</p>
<p>fmt.Println(app.Listen(":3000"))
}</p>
<p>```</p>
<p>Run the server and send a POST request with a large numeric key in form data, such as:</p>
<p>```bash
curl -v -X POST localhost:3000 --data-raw 'test.18446744073704' \
  -H 'Content-Type: application/x-www-form-urlencoded'
```</p>
<p>### Relevant Code Snippet</p>
<p>Within the decoder's [decode method](https://github.com/gofiber/fiber/blob/v2.52.8/internal/schema/decoder.go#L249):</p>
<p>```go
idx := parts[0].index
if v.IsNil() || v.Len…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qx2q-88mx-vhg7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15434-1</id>
    <title>openSUSE-SU-2025:15434-1 — govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media</title>
    <updated>2026-10-03T00:33:58.285172+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15434-1"/>
  </entry>
</feed>
