<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T18:26:14.857435+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265967</id>
    <title>EUVD-2026-265967</title>
    <updated>2026-10-09T18:26:14.859645+00:00</updated>
    <content>EUVD-2026-265967</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265967"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23735</id>
    <title>fkie_cve-2026-23735</title>
    <updated>2026-10-09T18:26:14.859677+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are made which trigger the same service, the context of the requests is mixed up in the service when the context is injected via @ExecutionContext(). ExecutionContext is often used to pass authentication tokens from incoming requests to services loading data from backend APIs. This vulnerability is fixed in 2.4.1 and 3.1.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-53wg-r69p-v3r7</id>
    <title>GHSA-53wg-r69p-v3r7 — GraphQL Modules has a Race Condition issue</title>
    <updated>2026-10-09T18:26:14.859710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: graphql-modules</p>
<p>### Summary
Originally reported as an issue #2613 but should be elevated to a security issue as the ExecutionContext is often used to pass authentication tokens from incoming requests to services loading data from backend APIs.</p>
<p>### Details
When 2 or more parallel requests are made which trigger the same service, the context of the requests is mixed up in the service when the context is injected via `@ExecutionContext()`</p>
<p>### PoC</p>
<p>In a new project/folder, create and install the following `package.json`:</p>
<p>```json
{
  "name": "GHSA-53wg-r69p-v3r7",
  "scripts": {
    "test": "jest"
  },
  "dependencies": {
    "graphql-modules": "2.4.0"
  },
  "devDependencies": {
    "@babel/plugin-proposal-class-properties": "^7.18.6",
    "@babel/plugin-proposal-decorators": "^7.28.6",
    "babel-plugin-parameter-decorator": "^1.0.16",
    "jest": "^29.7.0",
    "reflect-metadata": "^0.2.2"
  }
}
```</p>
<p>with:</p>
<p>```
npm i
```</p>
<p>configure `babel.config.json` using:</p>
<p>```json
{
  "plugins": [
    ["@babel/plugin-proposal-decorators", { "legacy": true }],
    "babel-plugin-parameter-decorator",
    "@babel/plugin-proposal-class-properties"
  ]
}
```</p>
<p>then write the following test `GHSA-53wg-r69p-v3r7.spec.ts`:</p>
<p>```js
require("reflect-metadata");
const {
  createApplication,
  createModule,
  Injectable,
  Scope,
  ExecutionContext,
  gql,
  testkit,
} = require("graphql-modules");</p>
<p>test("accessing a singleton provider context during another asynchronous execution", async () =&gt; {
  @Injectable({ scop…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-53wg-r69p-v3r7"/>
  </entry>
</feed>
