<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:02:53.325206+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338098</id>
    <title>EUVD-2026-338098</title>
    <updated>2026-10-06T09:02:53.382580+00:00</updated>
    <content>EUVD-2026-338098</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338098"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61449</id>
    <title>fkie_cve-2026-61449</title>
    <updated>2026-10-06T09:02:53.382631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']) and rejects archives exceeding system.gpm.archive.max_uncompressed_size before extraction. Because this declared size is attacker-forgeable and is not cross-checked against the actual inflated stream, a crafted archive declaring tiny per-entry sizes passes the cap while extractTo() writes the real, much larger content, filling disk or exhausting inodes. The archive must be supplied by a package source or admin upload (admin/operator trust). Fixed in 2.0.2. This is an incomplete fix for GHSA-928x-9mpw-8h56.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-61449"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8h9x-89f2-m7x3</id>
    <title>GHSA-8h9x-89f2-m7x3 — Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer</title>
    <updated>2026-10-06T09:02:53.382686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: getgrav/grav</p>
<p>### Summary</p>
<p>The decompression-bomb bound added in 2.0.1 (commit 1c1003c) sums `ZipArchive::statIndex($i)['size']` and rejects an archive whose declared uncompressed total exceeds `system.gpm.archive.max_uncompressed_size` (default 1 GiB) before extracting (`ZipArchiver.php:77-86`; same logic in `GPM\Installer::unZip` at `Installer.php:228-238`). `statIndex()['size']` is the uncompressed size declared in the ZIP central directory, which is attacker-forgeable and is not checked against the actual inflated stream. An archive declaring 1 byte per entry passes the cap while `extractTo()` writes the real (large) content. The entry-count and nesting-depth caps count real structure and still hold; only the size dimension is defeated, so the disk-fill / inode-exhaustion case the bound targets is not prevented. Incomplete fix for GHSA-928x-9mpw-8h56.</p>
<p>### Details</p>
<p>`extract()`/`unZip()` validate every entry up front, then call `Folder::create` + `extractTo`. The size check is:</p>
<p>```php
$totalSize += (int) $stat['size'];          // declared central-directory size
if ($maxSize &gt; 0 &amp;&amp; $totalSize &gt; $maxSize) { ... reject ... }
```</p>
<p>`$stat['size']` is read from the central directory, which the archive author writes. libzip does not cross-check declared-vs-actual size during `extractTo`, so a forged-small value passes the gate and the real stream inflates to disk. The `max_files` (entry count) and `max_depth` (entry-name segments) checks are not forgeable this way.</p>
<p>### PoC</p>
<p>Build a 10 KiB…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8h9x-89f2-m7x3"/>
  </entry>
</feed>
