<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:36:59.935642+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-25480</id>
    <title>CVE-2026-25480 — FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)</title>
    <updated>2026-10-05T15:36:59.937367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> litestar-org litestar</p>
<p>Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separators, creating key collisions. When FileStore is used as response-cache backend, an unauthenticated remote attacker can trigger cache key collisions via crafted paths, causing one URL to serve cached responses of another (cache poisoning/mixup). This vulnerability is fixed in 2.20.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-25480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vxqx-rh46-q2pg</id>
    <title>GHSA-vxqx-rh46-q2pg — Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)</title>
    <updated>2026-10-05T15:36:59.937423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: litestar</p>
<p>### Summary
FileStore maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separators, creating key collisions. When FileStore is used as response-cache backend, an unauthenticated remote attacker can trigger cache key collisions via crafted paths, causing one URL to serve cached responses of another (cache poisoning/mixup)</p>
<p>### Details
litestar.stores.file._safe_file_name() normalizes input with unicodedata.normalize("NFKD", name) and builds the filename by concatenating c if alphanumeric else str(ord(c)) (no delimiter).
This transformation is not injective, e.g.:</p>
<p>- "k-" and "k45" both become "k45" (because - ord('-') == 45)
- "k/\n" becomes "k4710", colliding with "k4710"
- "K" (Kelvin sign) normalizes to "K", colliding with "K"</p>
<p>When used in response caching, the default cache key includes request path and sorted query params, which are attacker-controlled.</p>
<p>### PoC</p>
<p>```
import asyncio, tempfile
from litestar.stores.file import FileStore</p>
<p>async def main():
    d = tempfile.mkdtemp(prefix="ls_filestore_poc_")
    store = FileStore(d, create_directories=True)
    await store.__aenter__()</p>
<p># 1) ASCII ord-collision: "-" -&gt; 45
    await store.set("k-", b"A")
    v = await store.get("k45")
    print("k-  -&gt;", v)
    print("k45 -&gt;", await store.get("k45"))
    if v == b"A":
        print("VULNERABLE: 'k-' collides with 'k45'")</p>
<p># 2) NFKD collision: Kelvin sign -&gt; K
    await store.set("K", b"B")   # U+212A
    v2 = await store.get…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vxqx-rh46-q2pg"/>
  </entry>
</feed>
