<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:57:11 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10864</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10864</link>
      <description>bdu:2026-10864</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10864</guid>
    </item>
    <item>
      <title>BREW-vite-CVE-2025-62522 — vite allows server.fs.deny bypass via backslash on Windows</title>
      <link>https://cve.radiocsirt.org/vuln/brew-vite-cve-2025-62522</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: vite&lt;/p&gt;
&lt;p&gt;### Summary
Files denied by [`server.fs.deny`](https://vitejs.dev/config/server-options.html#server-fs-deny) were sent if the URL ended with `\` when the dev server is running on Windows.&lt;/p&gt;
&lt;p&gt;### Impact
Only apps that match the following conditions are affected:&lt;/p&gt;
&lt;p&gt;- explicitly exposes the Vite dev server to the network (using --host or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))
- running the dev server on Windows&lt;/p&gt;
&lt;p&gt;### Details
`server.fs.deny` can contain patterns matching against files (by default it includes `.env`, `.env.*`, `*.{crt,pem}` as such patterns). These patterns were able to bypass by using a back slash(`\`). The root cause is that `fs.readFile(&amp;#39;/foo.png/&amp;#39;)` loads `/foo.png`.&lt;/p&gt;
&lt;p&gt;### PoC
```shell
npm create vite@latest
cd vite-project/
cat &amp;#34;secret&amp;#34; &amp;gt; .env
npm install
npm run dev
curl --request-target /.env\ http://localhost:5173
```
&amp;lt;img width=&amp;#34;1593&amp;#34; height=&amp;#34;616&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/36212f4e-1d3c-4686-b16f-16b35ca9e175&amp;#34; /&amp;gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: vite&lt;/p&gt;
&lt;p&gt;### Summary
Files denied by [`server.fs.deny`](https://vitejs.dev/config/server-options.html#server-fs-deny) were sent if the URL ended with `\` when the dev server is running on Windows.&lt;/p&gt;
&lt;p&gt;### Impact
Only apps that match the following conditions are affected:&lt;/p&gt;
&lt;p&gt;- explicitly exposes the Vite dev server to the network (using --host or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))
- running the dev server on Windows&lt;/p&gt;
&lt;p&gt;### Details
`server.fs.deny` can contain patterns matching against files (by default it includes `.env`, `.env.*`, `*.{crt,pem}` as such patterns). These patterns were able to bypass by using a back slash(`\`). The root cause is that `fs.readFile(&amp;#39;/foo.png/&amp;#39;)` loads `/foo.png`.&lt;/p&gt;
&lt;p&gt;### PoC
```shell
npm create vite@latest
cd vite-project/
cat &amp;#34;secret&amp;#34; &amp;gt; .env
npm install
npm run dev
curl --request-target /.env\ http://localhost:5173
```
&amp;lt;img width=&amp;#34;1593&amp;#34; height=&amp;#34;616&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/36212f4e-1d3c-4686-b16f-16b35ca9e175&amp;#34; /&amp;gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-vite-cve-2025-62522</guid>
    </item>
    <item>
      <title>EUVD-2026-255465</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255465</link>
      <description>EUVD-2026-255465</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255465</guid>
    </item>
    <item>
      <title>fkie_cve-2025-62522</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-62522</link>
      <description>&lt;p&gt;Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows. Only apps explicitly exposing the Vite dev server to the network and running the dev server on Windows were affected. This issue has been patched in versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows. Only apps explicitly exposing the Vite dev server to the network and running the dev server on Windows were affected. This issue has been patched in versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-62522</guid>
    </item>
    <item>
      <title>GHSA-93m4-6634-74q7 — vite allows server.fs.deny bypass via backslash on Windows</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-93m4-6634-74q7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vite&lt;/p&gt;
&lt;p&gt;### Summary
Files denied by [`server.fs.deny`](https://vitejs.dev/config/server-options.html#server-fs-deny) were sent if the URL ended with `\` when the dev server is running on Windows.&lt;/p&gt;
&lt;p&gt;### Impact
Only apps that match the following conditions are affected:&lt;/p&gt;
&lt;p&gt;- explicitly exposes the Vite dev server to the network (using --host or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))
- running the dev server on Windows&lt;/p&gt;
&lt;p&gt;### Details
`server.fs.deny` can contain patterns matching against files (by default it includes `.env`, `.env.*`, `*.{crt,pem}` as such patterns). These patterns were able to bypass by using a back slash(`\`). The root cause is that `fs.readFile(&amp;#39;/foo.png/&amp;#39;)` loads `/foo.png`.&lt;/p&gt;
&lt;p&gt;### PoC
```shell
npm create vite@latest
cd vite-project/
cat &amp;#34;secret&amp;#34; &amp;gt; .env
npm install
npm run dev
curl --request-target /.env\ http://localhost:5173
```
&amp;lt;img width=&amp;#34;1593&amp;#34; height=&amp;#34;616&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/36212f4e-1d3c-4686-b16f-16b35ca9e175&amp;#34; /&amp;gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vite&lt;/p&gt;
&lt;p&gt;### Summary
Files denied by [`server.fs.deny`](https://vitejs.dev/config/server-options.html#server-fs-deny) were sent if the URL ended with `\` when the dev server is running on Windows.&lt;/p&gt;
&lt;p&gt;### Impact
Only apps that match the following conditions are affected:&lt;/p&gt;
&lt;p&gt;- explicitly exposes the Vite dev server to the network (using --host or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host))
- running the dev server on Windows&lt;/p&gt;
&lt;p&gt;### Details
`server.fs.deny` can contain patterns matching against files (by default it includes `.env`, `.env.*`, `*.{crt,pem}` as such patterns). These patterns were able to bypass by using a back slash(`\`). The root cause is that `fs.readFile(&amp;#39;/foo.png/&amp;#39;)` loads `/foo.png`.&lt;/p&gt;
&lt;p&gt;### PoC
```shell
npm create vite@latest
cd vite-project/
cat &amp;#34;secret&amp;#34; &amp;gt; .env
npm install
npm run dev
curl --request-target /.env\ http://localhost:5173
```
&amp;lt;img width=&amp;#34;1593&amp;#34; height=&amp;#34;616&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/36212f4e-1d3c-4686-b16f-16b35ca9e175&amp;#34; /&amp;gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-93m4-6634-74q7</guid>
    </item>
    <item>
      <title>ICSA-26-071-03 — Siemens SIDIS Prime</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-071-03</link>
      <description>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-071-03</guid>
    </item>
    <item>
      <title>NCSC-2026-0079 — Kwetsbaarheden verholpen in Siemens producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0079</link>
      <description>NCSC-2026-0079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0079</guid>
    </item>
    <item>
      <title>SSA-485750 — SSA-485750: Multiple Vulnerabilities in SIDIS Prime Before V4.0.800</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-485750</link>
      <description>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-485750</guid>
    </item>
  </channel>
</rss>
