<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T09:03:50.220292+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364083</id>
    <title>EUVD-2026-364083</title>
    <updated>2026-10-02T09:03:50.268216+00:00</updated>
    <content>EUVD-2026-364083</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84469</id>
    <title>fkie_cve-2026-84469</title>
    <updated>2026-10-02T09:03:50.268256+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's body, querystring, params, or headers schema to deny all input, fastify treats it as a missing schema, compiles no validator, and runs the route handler on any request. An unauthenticated remote client can therefore reach a handler that a valid deny-all schema was intended to make unreachable, a complete validation bypass that can lead to unauthorized state changes or execution of disabled operations. Users should upgrade to fastify 5.12.2 or later.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-84469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hwr6-493r-vm6h</id>
    <title>GHSA-hwr6-493r-vm6h — fastify vulnerable to request validation bypass via skipped boolean false schemas</title>
    <updated>2026-10-02T09:03:50.268302+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fastify</p>
<p>### Impact</p>
<p>Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean `false` as a valid schema that rejects every instance, but because `false` is falsy, a route that set `body`, `querystring`, `params`, or `headers` to `false` had that part left uncompiled: no validator was attached and the request reached the handler. An application that used `false` as a deny-all schema to make a route unreachable was therefore fully bypassed, and an unauthenticated remote client could reach the handler with any input. The same applied to the documented `query` alias for `querystring`. This is a complete bypass rather than a weak-schema issue, since `false` is the strongest JSON Schema assertion and must always fail.</p>
<p>### Patches</p>
<p>Request-part schemas are now selected by an explicit presence check rather than truthiness, so a boolean `false` (or `true`) schema is compiled and enforced, including through the `query` alias. Patched in fastify `5.12.2`. The fix is also included in the `6.0.0` release.</p>
<p>### Workarounds</p>
<p>If upgrading is not immediately possible, express a deny-all request schema with an always-failing object schema instead of the boolean `false` (for example `{ "not": {} }`), or reject the request in an `onRequest` hook.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hwr6-493r-vm6h"/>
  </entry>
</feed>
