<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T06:57:52.946841+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1137</id>
    <title>certfr-2025-avi-1137 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-08T06:57:52.993734+00:00</updated>
    <content>certfr-2025-avi-1137</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1137"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-251713</id>
    <title>EUVD-2026-251713</title>
    <updated>2026-10-08T06:57:52.993773+00:00</updated>
    <content>EUVD-2026-251713</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-251713"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-57822</id>
    <title>fkie_cve-2025-57822</title>
    <updated>2026-10-08T06:57:52.993787+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorrectly forwarded user-supplied headers. This vulnerability has been fixed in Next.js versions 14.2.32 and 15.4.7. All users implementing custom middleware logic in self-hosted environments are strongly encouraged to upgrade and verify correct usage of the next() function.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-57822"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4342-x723-ch2f</id>
    <title>GHSA-4342-x723-ch2f — Next.js Improper Middleware Redirect Handling Leads to SSRF</title>
    <updated>2026-10-08T06:57:52.993818+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: next</p>
<p>A vulnerability in **Next.js Middleware** has been fixed in **v14.2.32** and **v15.4.7**. The issue occurred when request headers were directly passed into `NextResponse.next()`. In self-hosted applications, this could allow Server-Side Request Forgery (SSRF) if certain sensitive headers from the incoming request were reflected back into the response.</p>
<p>All users implementing custom middleware logic in self-hosted environments are strongly encouraged to upgrade and verify correct usage of the `next()` function.</p>
<p>More details at [Vercel Changelog](https://vercel.com/changelog/cve-2025-57822)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4342-x723-ch2f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1934</id>
    <title>WID-SEC-W-2025-1934 — Vercel Next.js: Mehrere Schwachstellen</title>
    <updated>2026-10-08T06:57:52.993844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Vercel Next.js ausnutzen, um vertrauliche Informationen offenzulegen, Daten zu manipulieren und so Server-Side Request Forgery- oder Phishing-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1934"/>
  </entry>
</feed>
