<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:27:58.205300+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-227559</id>
    <title>EUVD-2026-227559</title>
    <updated>2026-10-06T17:27:58.261277+00:00</updated>
    <content>EUVD-2026-227559</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-227559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-31481</id>
    <title>fkie_cve-2025-31481</title>
    <updated>2026-10-06T17:27:58.261317+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-31481"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cg3c-245w-728m</id>
    <title>GHSA-cg3c-245w-728m — GraphQL query operations security can be bypassed</title>
    <updated>2026-10-06T17:27:58.261352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: api-platform/graphql, Packagist: api-platform/core</p>
<p>### Summary</p>
<p>Using the Relay special `node` type you can bypass the configured security on an operation.</p>
<p>### Details</p>
<p>Here is an example of how to apply security configurations for the GraphQL operations:</p>
<p>```php
#[ApiResource(
    security: "is_granted('ROLE_USER')",
    operations: [ /* ... */ ],
    graphQlOperations: [
        new Query(security: "is_granted('ROLE_USER')"),
        //...
    ],
)]
class Book { /* ... */ }
```</p>
<p>This indeed checks `is_granted('ROLE_USER')` as expected for a GraphQL query like the following:</p>
<p>```php
‌query {
    book(id: "/books/1") {
        title
    }
}
```</p>
<p>But the security check can be bypassed by using the `node` field (that is available by default) on the root query type like that:</p>
<p>```php
‌query {
    node(id: "/books/1") {
        ... on Book {
            title
        }
    }
}
```</p>
<p>This does not execute any security checks and can therefore be used to access any entity without restrictions by everyone that has access to the API.</p>
<p>### Impact</p>
<p>Everyone using GraphQl with the `security` attribute. Not sure whereas this works with custom resolvers nor if this also applies on mutation.</p>
<p>Patched at https://github.com/api-platform/core/commit/60747cc8c2fb855798c923b5537888f8d0969568</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cg3c-245w-728m"/>
  </entry>
</feed>
