<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:21:41.403140+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0641</id>
    <title>certfr-2026-avi-0641 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T11:21:41.454189+00:00</updated>
    <content>certfr-2026-avi-0641</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0641"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221</id>
    <title>Withdrawn: CLEANSTART-2026-BE61221 — Security fixes for CVE-2025-62718, CVE-2025-69873, CVE-2026-29045, CVE-2026-29085, CVE-2026-29086, CVE-2026-29087, CVE-…</title>
    <updated>2026-10-03T11:21:41.454231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: opensearch-dashboards-fips</p>
<p>Multiple security vulnerabilities affect the opensearch-dashboards-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-274832</id>
    <title>EUVD-2026-274832</title>
    <updated>2026-10-03T11:21:41.454272+00:00</updated>
    <content>EUVD-2026-274832</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-274832"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29087</id>
    <title>fkie_cve-2026-29087</title>
    <updated>2026-10-03T11:21:41.454286+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middleware does not run but the static file is still served. This issue has been patched in version 1.19.10.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-29087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wc8c-qw6v-h7f6</id>
    <title>GHSA-wc8c-qw6v-h7f6 — @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware</title>
    <updated>2026-10-03T11:21:41.454311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @hono/node-server</p>
<p>## Summary</p>
<p>When using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting `/admin/*`), inconsistent URL decoding can allow protected static resources to be accessed without authorization.</p>
<p>In particular, paths containing encoded slashes (`%2F`) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middleware does not run but the static file is still served.</p>
<p>## Details</p>
<p>The routing layer and the node-server static handler normalize request paths differently. The router preserves `%2F` as a literal string when matching routes, while the static handler decodes `%2F` into `/` before resolving the filesystem path.</p>
<p>Example request:</p>
<p>- `/admin%2Fsecret.html`</p>
<p>This may:
- fail to match middleware intended for `/admin/*`, but
- still be resolved by the static handler as `/admin/secret.html` under the configured static root.</p>
<p>This does not allow access outside the configured static root and is not a path traversal vulnerability.</p>
<p>## Impact</p>
<p>An unauthenticated attacker could bypass route-based authorization protections for protected static resources by supplying paths containing encoded slashes.</p>
<p>Applications relying solely on route-based middleware to protect static subpaths under the same static root may have exposed those resources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wc8c-qw6v-h7f6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1007</id>
    <title>WID-SEC-W-2026-1007 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:21:41.454348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1007"/>
  </entry>
</feed>
