<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T13:05:02.631598+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-317422</id>
    <title>EUVD-2026-317422</title>
    <updated>2026-10-07T13:05:02.678376+00:00</updated>
    <content>EUVD-2026-317422</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-317422"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42190</id>
    <title>fkie_cve-2026-42190</title>
    <updated>2026-10-07T13:05:02.678419+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsdk apply HTTP method enforcement but no origin validation. A request originating from a different origin that the browser treats as same-site can invoke a server action with the victim's session cookie attached. This issue has been patched in version 1.2.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42190"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m2m6-cff5-3w7c</id>
    <title>GHSA-m2m6-cff5-3w7c — RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions</title>
    <updated>2026-10-07T13:05:02.678456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: rwsdk</p>
<p>### Summary</p>
<p>Server actions in `rwsdk` apply HTTP method enforcement but no origin validation. A request originating from a different origin that the browser treats as same-site can invoke a server action with the victim's session cookie attached.</p>
<p>### Impact</p>
<p>An attacker who controls any origin the browser considers same-site with the deployed app can induce an authenticated victim's browser to invoke arbitrary server actions. The exposure depends on deployment shape:</p>
<p>- Apps deployed on custom domains (for example `app.example.com`) are exposed whenever the attacker controls any sibling subdomain under the same registrable domain. Plausible vectors include subdomain takeover of stale DNS records pointing at third-party services, cross-site scripting on a sibling application, or content served from a user-content subdomain.
- Apps deployed on platform-suffix domains on the Public Suffix List (`*.workers.dev`, `*.pages.dev`) are not exposed to the sibling-subdomain vector, because sibling subdomains under those suffixes are treated as cross-site.
- In local development, `localhost` on any other port is treated as same-site with the app's dev server. A separate process running on the developer's machine can invoke server actions against the dev server.</p>
<p>The attacker cannot read action responses (`mode: "no-cors"` yields opaque responses). Impact is therefore limited to side effects of action invocation: writes, state changes, and any externally observable action the applicati…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m2m6-cff5-3w7c"/>
  </entry>
</feed>
