<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T01:04:04.775834+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276896</id>
    <title>EUVD-2026-276896</title>
    <updated>2026-10-06T01:04:04.810333+00:00</updated>
    <content>EUVD-2026-276896</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276896"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-3635</id>
    <title>fkie_cve-2026-3635</title>
    <updated>2026-10-06T01:04:04.810450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Summary
When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request.protocol and request.host getters read X-Forwarded-Proto and X-Forwarded-Host headers from any connection — including connections from untrusted IPs. This allows an attacker connecting directly to Fastify (bypassing the proxy) to spoof both the protocol and host seen by the application.</p>
<p>Affected Versions
fastify &lt;= 5.8.2</p>
<p>Impact
Applications using request.protocol or request.host for security decisions (HTTPS enforcement, secure cookie flags, CSRF origin checks, URL construction, host-based routing) are affected when trustProxy is configured with a restrictive trust function.</p>
<p>When trustProxy: true (trust everything), both host and protocol trust all forwarded headers — this is expected behavior. The vulnerability only manifests with restrictive trust configurations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-3635"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-444r-cwp2-x5xf</id>
    <title>GHSA-444r-cwp2-x5xf — fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections</title>
    <updated>2026-10-06T01:04:04.810662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fastify</p>
<p>## Summary</p>
<p>When `trustProxy` is configured with a restrictive trust function (e.g., a specific IP like `trustProxy: '10.0.0.1'`, a subnet, a hop count, or a custom function), the `request.protocol` and `request.host` getters read `X-Forwarded-Proto` and `X-Forwarded-Host` headers from any connection — including connections from untrusted IPs. This allows an attacker connecting directly to Fastify (bypassing the proxy) to spoof both the protocol and host seen by the application.</p>
<p>## Affected Versions</p>
<p>fastify &lt;= 5.8.2</p>
<p>## Impact</p>
<p>Applications using `request.protocol` or `request.host` for security decisions (HTTPS enforcement, secure cookie flags, CSRF origin checks, URL construction, host-based routing) are affected when `trustProxy` is configured with a restrictive trust function.</p>
<p>When `trustProxy: true` (trust everything), both `host` and `protocol` trust all forwarded headers — this is expected behavior. The vulnerability only manifests with restrictive trust configurations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-444r-cwp2-x5xf"/>
  </entry>
</feed>
