<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:05:30 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-266702</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266702</link>
      <description>EUVD-2026-266702</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266702</guid>
    </item>
    <item>
      <title>fkie_cve-2026-24398</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24398</link>
      <description>&lt;p&gt;Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4 octet values are within the valid range of 0-255, allowing attackers to craft malformed IP addresses that bypass IP-based access controls. Version 4.11.7 contains a patch for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4 octet values are within the valid range of 0-255, allowing attackers to craft malformed IP addresses that bypass IP-based access controls. Version 4.11.7 contains a patch for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-24398</guid>
    </item>
    <item>
      <title>GHSA-r354-f388-2fhh — Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r354-f388-2fhh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: hono&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4 octet values are within the valid range of 0-255, allowing attackers to craft malformed IP addresses that bypass IP-based access controls.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in two components:&lt;/p&gt;
&lt;p&gt;1. **Permissive regex pattern:** The `IPV4_REGEX (/^[0-9]{0,3}\.[0-9]{0,3}\.[0-9]{0,3}\.[0-9]{0,3}$/)` accepts octet values greater than 255 (e.g., `999`).
2. **Unsafe binary conversion:** The `convertIPv4ToBinary` function does not validate octet ranges before performing bitwise operations. When an octet exceeds 255, it overflows into adjacent octets during the bit-shift calculation.&lt;/p&gt;
&lt;p&gt;For example, the IP address `1.2.2.355` is accepted and converts to the same binary value as 1.2.3.99:&lt;/p&gt;
&lt;p&gt;* `355` = `256 + 99` = `0x163`
* After bit-shifting: `(1 &amp;lt;&amp;lt; 24) + (2 &amp;lt;&amp;lt; 16) + (2 &amp;lt;&amp;lt; 8) + 355` = `0x01020363` = `1.2.3.99`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker can bypass IP-based restrictions by crafting malformed IP addresses:&lt;/p&gt;
&lt;p&gt;* **Blocklist bypass:** If `1.2.3.0/24` is blocked, an attacker can use `1.2.2.355` (or similar) to bypass the restriction.
* **Allowlist bypass:** Requests from unauthorized IP ranges may be incorrectly permitted.&lt;/p&gt;
&lt;p&gt;This is exploitable when the application relies on client-provided IP addresses (e.g., `X-Forwarded-For header`) for access control decisions.&lt;/p&gt;
&lt;p&gt;## Affected Compo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: hono&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4 octet values are within the valid range of 0-255, allowing attackers to craft malformed IP addresses that bypass IP-based access controls.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in two components:&lt;/p&gt;
&lt;p&gt;1. **Permissive regex pattern:** The `IPV4_REGEX (/^[0-9]{0,3}\.[0-9]{0,3}\.[0-9]{0,3}\.[0-9]{0,3}$/)` accepts octet values greater than 255 (e.g., `999`).
2. **Unsafe binary conversion:** The `convertIPv4ToBinary` function does not validate octet ranges before performing bitwise operations. When an octet exceeds 255, it overflows into adjacent octets during the bit-shift calculation.&lt;/p&gt;
&lt;p&gt;For example, the IP address `1.2.2.355` is accepted and converts to the same binary value as 1.2.3.99:&lt;/p&gt;
&lt;p&gt;* `355` = `256 + 99` = `0x163`
* After bit-shifting: `(1 &amp;lt;&amp;lt; 24) + (2 &amp;lt;&amp;lt; 16) + (2 &amp;lt;&amp;lt; 8) + 355` = `0x01020363` = `1.2.3.99`&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker can bypass IP-based restrictions by crafting malformed IP addresses:&lt;/p&gt;
&lt;p&gt;* **Blocklist bypass:** If `1.2.3.0/24` is blocked, an attacker can use `1.2.2.355` (or similar) to bypass the restriction.
* **Allowlist bypass:** Requests from unauthorized IP ranges may be incorrectly permitted.&lt;/p&gt;
&lt;p&gt;This is exploitable when the application relies on client-provided IP addresses (e.g., `X-Forwarded-For header`) for access control decisions.&lt;/p&gt;
&lt;p&gt;## Affected Compo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r354-f388-2fhh</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0574 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0574</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0574</guid>
    </item>
  </channel>
</rss>
