<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T19:52:58.762735+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-263813</id>
    <title>EUVD-2026-263813</title>
    <updated>2026-10-08T19:52:58.765104+00:00</updated>
    <content>EUVD-2026-263813</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-263813"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68130</id>
    <title>fkie_cve-2025-68130</title>
    <updated>2026-10-08T19:52:58.765137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`'s `formDataToObject` function, which is used by the Next.js App Router adapter. An attacker can pollute `Object.prototype` by submitting specially crafted FormData field names, potentially leading to authorization bypass, denial of service, or other security impacts. Note that this vulnerability is only present when using `experimental_caller` / `experimental_nextAppDirCaller`. Versions 10.45.3 and 11.8.0 fix the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-43p4-m455-4f4j</id>
    <title>GHSA-43p4-m455-4f4j — tRPC has possible prototype pollution in `experimental_nextAppDirCaller`</title>
    <updated>2026-10-08T19:52:58.765171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @trpc/server</p>
<p>&gt; Note that this vulnerability is only present when using `experimental_caller` / `experimental_nextAppDirCaller`.</p>
<p>## Summary</p>
<p>A Prototype Pollution vulnerability exists in `@trpc/server`'s `formDataToObject` function, which is used by the Next.js App Router adapter. An attacker can pollute `Object.prototype` by submitting specially crafted FormData field names, potentially leading to authorization bypass, denial of service, or other security impacts.</p>
<p>## Affected Versions</p>
<p>- **Package:** `@trpc/server`
- **Affected Versions:** &gt;=10.27.0
- **Vulnerable Component:** `formDataToObject()` in `src/unstable-core-do-not-import/http/formDataToObject.ts`</p>
<p>## Vulnerability Details</p>
<p>### Root Cause</p>
<p>The `set()` function in `formDataToObject.ts` recursively processes FormData field names containing bracket/dot notation (e.g., `user[name]`, `user.address.city`) to create nested objects. However, it does **not** validate or sanitize dangerous keys like `__proto__`, `constructor`, or `prototype`.</p>
<p>### Vulnerable Code</p>
<p>```typescript
// packages/server/src/unstable-core-do-not-import/http/formDataToObject.ts
function set(obj, path, value) {
  if (path.length &gt; 1) {
    const newPath = [...path];
    const key = newPath.shift();  // ← No validation of dangerous keys
    const nextKey = newPath[0];</p>
<p>if (!obj[key]) {  // ← Accesses obj["__proto__"] which returns Object.prototype
      obj[key] = isNumberString(nextKey) ? [] : {};
    }
    
    set(obj[key], newPath, value);  // ← Recursiv…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-43p4-m455-4f4j"/>
  </entry>
</feed>
