<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T22:22:15.860816+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338350</id>
    <title>EUVD-2026-338350</title>
    <updated>2026-10-08T22:22:15.864109+00:00</updated>
    <content>EUVD-2026-338350</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338350"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48795</id>
    <title>fkie_cve-2026-48795</title>
    <updated>2026-10-08T22:22:15.864150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted and constructor.prototype still caused lodash _.set() via @poppinss/utils to create plain intermediate objects and pollute Object.prototype. This issue is fixed in versions 10.1.5 and 11.0.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qcm7-3vpr-hj5h</id>
    <title>GHSA-qcm7-3vpr-hj5h — @adonisjs/bodyparser has an incomplete fix for CVE-2026-25754</title>
    <updated>2026-10-08T22:22:15.864186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @adonisjs/bodyparser</p>
<p>### Summary</p>
<p>The fix for [GHSA-f5x2-vj4h-vg4c](https://github.com/adonisjs/core/security/advisories/GHSA-f5x2-vj4h-vg4c) / CVE-2026-25754 introduced in commit [`40e1c71`](https://github.com/adonisjs/bodyparser/commit/40e1c71f958cffb74f6b91bed6630dca979062ed) is incomplete and can be bypassed through nested prototype pollution payloads.</p>
<p>The original patch replaced the internal `FormFields` storage object with `Object.create(null)`, preventing direct payloads such as `__proto__.polluted`. However, payloads containing a non-dangerous segment before `__proto__` or `constructor.prototype`, such as `user.__proto__.polluted`, still lead to `Object.prototype` pollution.</p>
<p>This issue is exploitable remotely through a single unauthenticated `multipart/form-data` request using the default configuration.</p>
<p>### Affected versions</p>
<p>- `&gt;= 10.1.3 &lt; 10.1.5`
- `&gt;= 11.0.0-next.9 &lt; 11.0.3`</p>
<p>### Details</p>
<p>The regression tests added by the original fix only covered direct payloads such as:</p>
<p>- `__proto__.polluted`
- `constructor.prototype.polluted`</p>
<p>These payloads are blocked because the root object no longer inherits from `Object.prototype`.</p>
<p>However, lodash `_.set()` (via `@poppinss/utils`) still creates intermediate objects using plain `{}` values. Once a normal segment is encountered, subsequent `__proto__` or `constructor.prototype` segments regain access to `Object.prototype`.</p>
<p>### Impact</p>
<p>An unauthenticated attacker can remotely pollute `Object.prototype` on any route accepting multipart/form-…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qcm7-3vpr-hj5h"/>
  </entry>
</feed>
