<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:22:52.253267+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09015</id>
    <title>bdu:2026-09015</title>
    <updated>2026-10-04T07:22:52.339006+00:00</updated>
    <content>bdu:2026-09015</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09015"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337330</id>
    <title>EUVD-2026-337330</title>
    <updated>2026-10-04T07:22:52.339043+00:00</updated>
    <content>EUVD-2026-337330</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33806</id>
    <title>fkie_cve-2026-33806</title>
    <updated>2026-10-04T07:22:52.339058+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Impact:</p>
<p>Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped.</p>
<p>This is a regression introduced in fastify &gt;= 5.3.2 by the fix for CVE-2025-32442</p>
<p>Patches:</p>
<p>Upgrade to fastify v5.8.5 or later.</p>
<p>Workarounds:</p>
<p>None. Upgrade to the patched version.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33806"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-247c-9743-5963</id>
    <title>GHSA-247c-9743-5963 — Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header</title>
    <updated>2026-10-04T07:22:52.339098+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fastify</p>
<p>### Summary
A validation bypass vulnerability exists in Fastify v5.x where request body validation schemas specified via `schema.body.content` can be completely circumvented by prepending a single space character (`\x20`) to the `Content-Type` header. The body is still parsed correctly as JSON (or any other content type), but schema validation is entirely skipped.
This is a regression introduced by commit [`f3d2bcb`](https://github.com/fastify/fastify/commit/f3d2bcb3963cd570a582e5d39aab01a9ae692fe4) (fix for [CVE-2025-32442](https://github.com/fastify/fastify/security/advisories/GHSA-mg2h-6x62-wpwc)).</p>
<p>### Details
The vulnerability is a **parser-validator differential** between two independent code paths that process the raw `Content-Type` header differently.
**Parser path** (`lib/content-type.js`, line ~67) applies `trimStart()` before processing:
```js
const type = headerValue.slice(0, sepIdx).trimStart().toLowerCase()
// ' application/json' → trimStart() → 'application/json' → body is parsed ✓
```</p>
<p>**Validator path** (`lib/validation.js`, line 272) splits on `/[ ;]/` before trimming:</p>
<p>```js
function getEssenceMediaType(header) {
  if (!header) return ''
  return header.split(/[ ;]/, 1)[0].trim().toLowerCase()
}
// ' application/json'.split(/[ ;]/, 1) → ['']  (splits on the leading space!)
// ''.trim() → ''
// context[bodySchema][''] → undefined → NO validator found → validation skipped!
```</p>
<p>The `ContentType` class applies `trimStart()` before processing, so the parser co…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-247c-9743-5963"/>
  </entry>
</feed>
