<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T07:43:48.364495+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276625</id>
    <title>EUVD-2026-276625</title>
    <updated>2026-10-06T07:43:48.412321+00:00</updated>
    <content>EUVD-2026-276625</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33131</id>
    <title>fkie_cve-2026-33131</title>
    <updated>2026-10-06T07:43:48.412374+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which extends FastURL) which allows middleware bypass. When event.url, event.url.hostname, or event.url._url is accessed, such as in a logging middleware, the _url getter constructs a URL from untrusted data, including the user-controlled Host header. Because H3's router resolves the route handler before middleware runs, an attacker can supply a crafted Host header (e.g., Host: localhost:3000/abchehe?) to make the middleware path check fail while the route handler still matches, effectively bypassing authentication or authorization middleware. This affects any application built on H3 (including Nitro/Nuxt) that accesses event.url properties in middleware guarding sensitive routes. The issue requires an immediate fix to prevent FastURL.href from being constructed with unsanitized, attacker-controlled input. Version 2.0.1-rc.15 contains a patch for this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3vj8-jmxq-cgj5</id>
    <title>GHSA-3vj8-jmxq-cgj5 — h3 has a middleware bypass with one gadget</title>
    <updated>2026-10-06T07:43:48.412438+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: h3</p>
<p># H3 NodeRequestUrl bugs</p>
<p>Vulnerable pieces of code : 
```js
import { H3, serve, defineHandler, getQuery, getHeaders, readBody, defineNodeHandler } from "h3";
let app = new H3()</p>
<p>const internalOnly = defineHandler((event, next) =&gt; {
  const token = event.headers.get("x-internal-key");</p>
<p>if (token !== "SUPERRANDOMCANNOTBELEAKED") {
    return new Response("Forbidden", { status: 403 });
  }</p>
<p>return next();
});
const logger = defineHandler((event, next) =&gt; {
    console.log("Logging : " +  event.url.hostname)
    return next() 
})
app.use(logger);
app.use("/internal/run", internalOnly);</p>
<p>app.get("/internal/run", () =&gt; {
  return "Internal OK";
});</p>
<p>serve(app, { port: 3001 });
```</p>
<p>The middleware is super safe now with just a logger and a middleware to block internal access.
But there's one problems here at the logger .
When it log out the ```event.url``` or ```event.url.hostname``` or ```event.url._url```</p>
<p>It will lead to trigger one specials method</p>
<p>```js 
// _url.mjs FastURL
get _url() {
    if (this.#url) return this.#url;
    this.#url = new NativeURL(this.href);
    this.#href = void 0;
    this.#protocol = void 0;
    this.#host = void 0;
    this.#pathname = void 0;
    this.#search = void 0;
    this.#searchParams = void 0;
    this.#pos = void 0;
    return this.#url;
}
```</p>
<p>The `NodeRequestUrl` is extends from `FastURL` so when we just access ```.url``` or trying to dump all data of this class . This function will be triggered !!</p>
<p>And as debugging , the `this.#…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3vj8-jmxq-cgj5"/>
  </entry>
</feed>
