<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:02:09 +0000</lastBuildDate>
    <item>
      <title>cnvd-2022-66495</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-66495</link>
      <description>cnvd-2022-66495</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-66495</guid>
    </item>
    <item>
      <title>EUVD-2026-232698</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232698</link>
      <description>EUVD-2026-232698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232698</guid>
    </item>
    <item>
      <title>fkie_cve-2022-31019</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31019</link>
      <description>&lt;p&gt;Vapor is a server-side Swift HTTP web framework. When using automatic content decoding an attacker can craft a request body that can make the server crash with the following request: `curl -d &amp;#34;array[_0][0][array][_0][0][array]$(for f in $(seq 1100); do echo -n &amp;#39;[_0][0][array]&amp;#39;; done)[string][_0]=hello%20world&amp;#34; http://localhost:8080/foo`. The issue is unbounded, attacker controlled stack growth which will at some point lead to a stack overflow and a process crash. This issue has been fixed in version 4.61.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vapor is a server-side Swift HTTP web framework. When using automatic content decoding an attacker can craft a request body that can make the server crash with the following request: `curl -d &amp;#34;array[_0][0][array][_0][0][array]$(for f in $(seq 1100); do echo -n &amp;#39;[_0][0][array]&amp;#39;; done)[string][_0]=hello%20world&amp;#34; http://localhost:8080/foo`. The issue is unbounded, attacker controlled stack growth which will at some point lead to a stack overflow and a process crash. This issue has been fixed in version 4.61.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-31019</guid>
    </item>
    <item>
      <title>GHSA-qvxg-wjxc-r4gg — Vapor vulnerable to denial of service in URLEncodedFormDecoder</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qvxg-wjxc-r4gg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; SwiftURL: github.com/vapor/vapor&lt;/p&gt;
&lt;p&gt;Vapor is an HTTP web framework for Swift. Vapor versions earlier than 4.61.1 are vulnerable to a denial of service in the URLEncodedFormDecoder.&lt;/p&gt;
&lt;p&gt;### Impact
When using automatic content decoding, e.g.&lt;/p&gt;
&lt;p&gt;```swift
app.post(&amp;#34;foo&amp;#34;) { request -&amp;gt; String in
  let foo = try request.content.decode(Foo.self)
  return &amp;#34;\(foo)&amp;#34;
}
```&lt;/p&gt;
&lt;p&gt;An attacker can craft a request body that can make the server crash with the following request:&lt;/p&gt;
&lt;p&gt;```
curl -d &amp;#34;array[_0][0][array][_0][0][array]$(for f in $(seq 1100); do echo -n &amp;#39;[_0][0][array]&amp;#39;; done)[string][_0]=hello%20world&amp;#34; http://localhost:8080/foo
```&lt;/p&gt;
&lt;p&gt;The issue is unbounded, attacker controlled stack growth which will at some point lead to a stack overflow.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in 4.61.1&lt;/p&gt;
&lt;p&gt;### Workarounds
If you don&amp;#39;t need to decode Form URL Encoded data, you can disable the `ContentConfiguration` so it won&amp;#39;t be used. E.g. in **configure.swift**&lt;/p&gt;
&lt;p&gt;```swift
var contentConfig = ContentConfiguration()
contentConfig.use(encoder: JSONEncoder.custom(dates: .iso8601), for: .json)
contentConfig.use(decoder: JSONDecoder.custom(dates: .iso8601), for: .json)
contentConfig.use(encoder: JSONEncoder.custom(dates: .iso8601), for: .jsonAPI)
contentConfig.use(decoder: JSONDecoder.custom(dates: .iso8601), for: .jsonAPI)
ContentConfiguration.global = contentConfig
```&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [the Vapor repo](https://github.com/vapor/vapor)
* Ask in [Vapor Discord](http://vapor.team)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; SwiftURL: github.com/vapor/vapor&lt;/p&gt;
&lt;p&gt;Vapor is an HTTP web framework for Swift. Vapor versions earlier than 4.61.1 are vulnerable to a denial of service in the URLEncodedFormDecoder.&lt;/p&gt;
&lt;p&gt;### Impact
When using automatic content decoding, e.g.&lt;/p&gt;
&lt;p&gt;```swift
app.post(&amp;#34;foo&amp;#34;) { request -&amp;gt; String in
  let foo = try request.content.decode(Foo.self)
  return &amp;#34;\(foo)&amp;#34;
}
```&lt;/p&gt;
&lt;p&gt;An attacker can craft a request body that can make the server crash with the following request:&lt;/p&gt;
&lt;p&gt;```
curl -d &amp;#34;array[_0][0][array][_0][0][array]$(for f in $(seq 1100); do echo -n &amp;#39;[_0][0][array]&amp;#39;; done)[string][_0]=hello%20world&amp;#34; http://localhost:8080/foo
```&lt;/p&gt;
&lt;p&gt;The issue is unbounded, attacker controlled stack growth which will at some point lead to a stack overflow.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in 4.61.1&lt;/p&gt;
&lt;p&gt;### Workarounds
If you don&amp;#39;t need to decode Form URL Encoded data, you can disable the `ContentConfiguration` so it won&amp;#39;t be used. E.g. in **configure.swift**&lt;/p&gt;
&lt;p&gt;```swift
var contentConfig = ContentConfiguration()
contentConfig.use(encoder: JSONEncoder.custom(dates: .iso8601), for: .json)
contentConfig.use(decoder: JSONDecoder.custom(dates: .iso8601), for: .json)
contentConfig.use(encoder: JSONEncoder.custom(dates: .iso8601), for: .jsonAPI)
contentConfig.use(decoder: JSONDecoder.custom(dates: .iso8601), for: .jsonAPI)
ContentConfiguration.global = contentConfig
```&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [the Vapor repo](https://github.com/vapor/vapor)
* Ask in [Vapor Discord](http://vapor.team)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qvxg-wjxc-r4gg</guid>
    </item>
    <item>
      <title>gsd-2022-31019</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-31019</link>
      <description>gsd-2022-31019</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-31019</guid>
    </item>
  </channel>
</rss>
