<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T08:10:37.806981+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-mongoose-2026-42334</id>
    <title>BIT-mongoose-2026-42334 — Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection</title>
    <updated>2026-10-06T08:10:37.868284+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: mongoose</p>
<p>Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to neutralize them. However, prior to the fix, $nor was not included in the set of logical operators that are recursively sanitized. Because $nor accepts an array (like $and and $or), and arrays do not trigger hasDollarKeys(), malicious operators such as $ne, $gt, or $regex could be injected inside a $nor clause without being sanitized. This vulnerability is fixed in 6.13.9, 7.8.9, 8.22.1, and 9.1.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-mongoose-2026-42334"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318582</id>
    <title>EUVD-2026-318582</title>
    <updated>2026-10-06T08:10:37.868385+00:00</updated>
    <content>EUVD-2026-318582</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42334</id>
    <title>fkie_cve-2026-42334</title>
    <updated>2026-10-06T08:10:37.868421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to neutralize them. However, prior to the fix, $nor was not included in the set of logical operators that are recursively sanitized. Because $nor accepts an array (like $and and $or), and arrays do not trigger hasDollarKeys(), malicious operators such as $ne, $gt, or $regex could be injected inside a $nor clause without being sanitized. This vulnerability is fixed in 6.13.9, 7.8.9, 8.22.1, and 9.1.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42334"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wpg9-53fq-2r8h</id>
    <title>GHSA-wpg9-53fq-2r8h — Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection</title>
    <updated>2026-10-06T08:10:37.868497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: mongoose</p>
<p>### Impact</p>
<p>This vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the `$nor` operator.</p>
<p>When sanitizeFilter is enabled, Mongoose wraps query operators in `$eq` to neutralize them. However, prior to the fix, `$nor` was not included in the set of logical operators that are recursively sanitized. Because `$nor` accepts an array (like `$and` and `$or`), and arrays do not trigger `hasDollarKeys()`, malicious operators such as `$ne`, `$gt`, or `$regex` could be injected inside a `$nor` clause without being sanitized.</p>
<p>This may lead to:</p>
<p>- Authentication bypass
- Unauthorized data access
- Data exfiltration</p>
<p>**Affected users:**</p>
<p>Applications that:</p>
<p>- Explicitly enable sanitizeFilter
- Pass unsanitized user-controlled input directly into query methods (e.g., `Model.findOne(req.body)`) and rely on `sanitizeFilter` to strip out query selectors</p>
<p>Applications that validate input schemas, whitelist fields, or avoid passing raw request bodies into queries are not affected. For example, `Model.findOne({ user: req.body.user, pwd: req.body.pwd })` is not affected.</p>
<p>### Patches</p>
<p>Patches have been released for all supported Mongoose release lines:</p>
<p>- `^6.13.9`
- `^7.8.9`
- `^8.22.1`
- `^9.1.6`</p>
<p>### Workarounds</p>
<p>Delete `$nor` keys, use an additional schema validation library, or write middleware to strip out `$nor` from query filters.</p>
<p>### Resources</p>
<p>sanitizeFilter documentation: https://mongoosejs.com/docs/api/mongoose.html#Mongoose.prototype.sanitiz…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wpg9-53fq-2r8h"/>
  </entry>
</feed>
