<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T23:59:42.133415+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-372000</id>
    <title>EUVD-2026-372000</title>
    <updated>2026-10-06T23:59:42.197837+00:00</updated>
    <content>EUVD-2026-372000</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-372000"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-86250</id>
    <title>fkie_cve-2026-86250</title>
    <updated>2026-10-06T23:59:42.197882+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to trigger an O(n²) cleanup loop that hangs the server process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-86250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q5pr-72pq-83v3</id>
    <title>GHSA-q5pr-72pq-83v3 — H3: Unbounded Chunked Cookie Count in Session Cleanup Loop may Lead to Denial of Service</title>
    <updated>2026-10-06T23:59:42.197929+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: h3</p>
<p>## Summary</p>
<p>The `setChunkedCookie()` and `deleteChunkedCookie()` functions in h3 trust the chunk count parsed from a user-controlled cookie value (`__chunked__N`) without any upper bound validation. An unauthenticated attacker can send a single request with a crafted cookie header (e.g., `Cookie: h3=__chunked__999999`) to any endpoint using sessions, causing the server to enter an O(n²) loop that hangs the process.</p>
<p>## Details</p>
<p>The chunked cookie system stores large cookie values by splitting them into numbered chunks. The main cookie stores a sentinel value `__chunked__N` indicating how many chunks exist. When setting a new chunked cookie, the code cleans up any previous chunks that are no longer needed.</p>
<p>The vulnerability is in `getChunkedCookieCount()` at `src/utils/cookie.ts:244-249`:</p>
<p>```typescript
function getChunkedCookieCount(cookie: string | undefined): number {
  if (!cookie?.startsWith(CHUNKED_COOKIE)) {
    return Number.NaN;
  }
  return Number.parseInt(cookie.slice(CHUNKED_COOKIE.length));
  // No upper bound check — attacker controls this value
}
```</p>
<p>This value is consumed without validation in the cleanup loop of `setChunkedCookie()` at `src/utils/cookie.ts:182-190`:</p>
<p>```typescript
const previousCookie = getCookie(event, name); // reads from request headers
if (previousCookie?.startsWith(CHUNKED_COOKIE)) {
  const previousChunkCount = getChunkedCookieCount(previousCookie);
  if (previousChunkCount &gt; chunkCount) {
    for (let i = chunkCount; i &lt;= previousChu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q5pr-72pq-83v3"/>
  </entry>
</feed>
