<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T04:26:58.546276+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326965</id>
    <title>EUVD-2026-326965</title>
    <updated>2026-10-08T04:26:58.607172+00:00</updated>
    <content>EUVD-2026-326965</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326965"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53721</id>
    <title>fkie_cve-2026-53721</title>
    <updated>2026-10-08T04:26:58.607251+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53721"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mm7m-92g8-7m47</id>
    <title>GHSA-mm7m-92g8-7m47 — Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher</title>
    <updated>2026-10-08T04:26:58.607304+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nuxt</p>
<p>## Impact</p>
<p>Nuxt looks up `routeRules` for the current navigation by calling
`getRouteRules({ path: to.path })` from the page-router plugin and the
no-pages router plugin. The compiled `routeRules` matcher (built on
`rou3`) performs case-sensitive matching, while vue-router is configured
with its default `sensitive: false` and matches paths case-insensitively.</p>
<p>The two routers therefore disagree on which rules apply to a given
request path: vue-router still matches the page record for
`/Admin/dashboard`, but the `routeRules` lookup for the same path
returns no match. Any `appMiddleware` declared via `routeRules` is never
added to the middleware set and never runs, on both SSR and client
navigations. The same path skips other path-keyed route rules in the
same way (`ssr`, `redirect`, `appLayout`, and the prerender / payload
hints used client-side).</p>
<p>For applications using `routeRules` with `appMiddleware` as an
authorization gate (a documented pattern), an attacker can flip the case
of any static segment in a protected URL (for example `/Admin/dashboard`
instead of `/admin/dashboard`) to render the protected page with the
middleware skipped. The server returns the fully server-rendered page
including any `useFetch` / `useAsyncData` results captured during SSR.</p>
<p>This is an instance of CWE-178 (Improper Handling of Case Sensitivity)
leading to CWE-863 (Incorrect Authorization) for apps that treat
`appMiddleware` as an authorization boundary.</p>
<p>## Mitigating factors</p>
<p>- Only affect…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mm7m-92g8-7m47"/>
  </entry>
</feed>
