<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T10:10:32.440770+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-332332</id>
    <title>EUVD-2026-332332</title>
    <updated>2026-10-07T10:10:32.496615+00:00</updated>
    <content>EUVD-2026-332332</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-332332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54164</id>
    <title>fkie_cve-2026-54164</title>
    <updated>2026-10-07T10:10:32.496655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's AbstractItemNormalizer does not validate the resource type returned when resolving relation IRIs, allowing type confusion where a resource of an unintended type can be silently assigned to a relation property. An attacker who can submit write requests (POST/PUT/PATCH) to an API Platform endpoint with writable relations can supply a relation IRI pointing to a resource of a different type than the relation's declared class. Because getResourceFromIri() does not pass an $operation to IriConverter::getResourceFromIri(), the is_a type guard at IriConverter.php:86 is skipped. For untyped relation properties (legacy @var-only style), the wrong-typed object is silently assigned, corrupting invariants and potentially feeding downstream logic that assumes the declared type (CWE-843). For typed properties (modern PHP 8.x), the substitution is blocked by Symfony's PropertyAccessor with an InvalidTypeException. This issue has been fixed in versions 4.1.30, 4.2.26 and 4.3.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54164"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9rjg-x2p2-h68h</id>
    <title>GHSA-9rjg-x2p2-h68h — API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource typ…</title>
    <updated>2026-10-07T10:10:32.496696+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: api-platform/core</p>
<p>## Summary</p>
<p>The API Platform serializer's `AbstractItemNormalizer` does not validate the resource type returned when resolving relation IRIs, allowing type confusion where a resource of an unintended type can be silently assigned to a relation property.</p>
<p>## Impact</p>
<p>An attacker who can submit write requests (POST/PUT/PATCH) to an API Platform endpoint with writable relations can supply a relation IRI pointing to a resource of a different type than the relation's declared class. Because `getResourceFromIri()` does not pass an `$operation` to `IriConverter::getResourceFromIri()`, the `is_a` type guard at `IriConverter.php:86` is skipped. For untyped relation properties (legacy `@var`-only style), the wrong-typed object is silently assigned, corrupting invariants and potentially feeding downstream logic that assumes the declared type (CWE-843). For typed properties (modern PHP 8.x), the substitution is blocked by Symfony's PropertyAccessor with an `InvalidTypeException`.</p>
<p>## Affected versions</p>
<p>- `api-platform/core` `&lt; 4.1.30`
- `api-platform/core` `&gt;= 4.2.0, &lt; 4.2.26`
- `api-platform/core` `&gt;= 4.3.0, &lt; 4.3.12`</p>
<p>Older major series (`2.x`, `3.x`) ship the same vulnerable code path and are end-of-life; no fix is planned.</p>
<p>## Patched versions</p>
<p>- `4.1.30`
- `4.2.26`
- `4.3.12`</p>
<p>## Fix</p>
<p>An `is_a` guard is added inside `AbstractItemNormalizer::getResourceFromIri()` (and the equivalent inline call sites on 4.1) so that a mismatched IRI throws `InvalidArgumentException`, mirroring the op…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9rjg-x2p2-h68h"/>
  </entry>
</feed>
