<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:32:36.764638+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10864</id>
    <title>bdu:2026-10864</title>
    <updated>2026-10-02T14:32:36.856055+00:00</updated>
    <content>bdu:2026-10864</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10864"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-vite-cve-2025-62522</id>
    <title>BREW-vite-CVE-2025-62522 — vite allows server.fs.deny bypass via backslash on Windows</title>
    <updated>2026-10-02T14:32:36.856093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: vite</p>
<p>### Summary
Files denied by [`server.fs.deny`](https://vitejs.dev/config/server-options.html#server-fs-deny) were sent if the URL ended with `\` when the dev server is running on Windows.</p>
<p>### Impact
Only apps that match the following conditions are affected:</p>
<p>- explicitly exposes the Vite dev server to the network (using --host or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))
- running the dev server on Windows</p>
<p>### Details
`server.fs.deny` can contain patterns matching against files (by default it includes `.env`, `.env.*`, `*.{crt,pem}` as such patterns). These patterns were able to bypass by using a back slash(`\`). The root cause is that `fs.readFile('/foo.png/')` loads `/foo.png`.</p>
<p>### PoC
```shell
npm create vite@latest
cd vite-project/
cat "secret" &gt; .env
npm install
npm run dev
curl --request-target /.env\ http://localhost:5173
```
&lt;img width="1593" height="616" alt="image" src="https://github.com/user-attachments/assets/36212f4e-1d3c-4686-b16f-16b35ca9e175" /&gt;</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-vite-cve-2025-62522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255465</id>
    <title>EUVD-2026-255465</title>
    <updated>2026-10-02T14:32:36.856136+00:00</updated>
    <content>EUVD-2026-255465</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-62522</id>
    <title>fkie_cve-2025-62522</title>
    <updated>2026-10-02T14:32:36.856151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows. Only apps explicitly exposing the Vite dev server to the network and running the dev server on Windows were affected. This issue has been patched in versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-62522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-93m4-6634-74q7</id>
    <title>GHSA-93m4-6634-74q7 — vite allows server.fs.deny bypass via backslash on Windows</title>
    <updated>2026-10-02T14:32:36.856175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vite</p>
<p>### Summary
Files denied by [`server.fs.deny`](https://vitejs.dev/config/server-options.html#server-fs-deny) were sent if the URL ended with `\` when the dev server is running on Windows.</p>
<p>### Impact
Only apps that match the following conditions are affected:</p>
<p>- explicitly exposes the Vite dev server to the network (using --host or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))
- running the dev server on Windows</p>
<p>### Details
`server.fs.deny` can contain patterns matching against files (by default it includes `.env`, `.env.*`, `*.{crt,pem}` as such patterns). These patterns were able to bypass by using a back slash(`\`). The root cause is that `fs.readFile('/foo.png/')` loads `/foo.png`.</p>
<p>### PoC
```shell
npm create vite@latest
cd vite-project/
cat "secret" &gt; .env
npm install
npm run dev
curl --request-target /.env\ http://localhost:5173
```
&lt;img width="1593" height="616" alt="image" src="https://github.com/user-attachments/assets/36212f4e-1d3c-4686-b16f-16b35ca9e175" /&gt;</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-93m4-6634-74q7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-071-03</id>
    <title>ICSA-26-071-03 — Siemens SIDIS Prime</title>
    <updated>2026-10-02T14:32:36.856209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-071-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0079</id>
    <title>NCSC-2026-0079 — Kwetsbaarheden verholpen in Siemens producten</title>
    <updated>2026-10-02T14:32:36.856312+00:00</updated>
    <content>NCSC-2026-0079</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-485750</id>
    <title>SSA-485750 — SSA-485750: Multiple Vulnerabilities in SIDIS Prime Before V4.0.800</title>
    <updated>2026-10-02T14:32:36.856378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-485750"/>
  </entry>
</feed>
