<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:32:52 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0641 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0641</link>
      <description>certfr-2026-avi-0641</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0641</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BE61221 — Security fixes for CVE-2025-62718, CVE-2025-69873, CVE-2026-29045, CVE-2026-29085, CVE-2026-29086, CVE-2026-29087, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the opensearch-dashboards-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the opensearch-dashboards-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221</guid>
    </item>
    <item>
      <title>EUVD-2026-274832</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274832</link>
      <description>EUVD-2026-274832</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274832</guid>
    </item>
    <item>
      <title>fkie_cve-2026-29087</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29087</link>
      <description>&lt;p&gt;@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server&amp;#39;s static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middleware does not run but the static file is still served. This issue has been patched in version 1.19.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server&amp;#39;s static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middleware does not run but the static file is still served. This issue has been patched in version 1.19.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-29087</guid>
    </item>
    <item>
      <title>GHSA-wc8c-qw6v-h7f6 — @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wc8c-qw6v-h7f6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @hono/node-server&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When using @hono/node-server&amp;#39;s static file serving together with route-based middleware protections (e.g. protecting `/admin/*`), inconsistent URL decoding can allow protected static resources to be accessed without authorization.&lt;/p&gt;
&lt;p&gt;In particular, paths containing encoded slashes (`%2F`) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middleware does not run but the static file is still served.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The routing layer and the node-server static handler normalize request paths differently. The router preserves `%2F` as a literal string when matching routes, while the static handler decodes `%2F` into `/` before resolving the filesystem path.&lt;/p&gt;
&lt;p&gt;Example request:&lt;/p&gt;
&lt;p&gt;- `/admin%2Fsecret.html`&lt;/p&gt;
&lt;p&gt;This may:
- fail to match middleware intended for `/admin/*`, but
- still be resolved by the static handler as `/admin/secret.html` under the configured static root.&lt;/p&gt;
&lt;p&gt;This does not allow access outside the configured static root and is not a path traversal vulnerability.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An unauthenticated attacker could bypass route-based authorization protections for protected static resources by supplying paths containing encoded slashes.&lt;/p&gt;
&lt;p&gt;Applications relying solely on route-based middleware to protect static subpaths under the same static root may have exposed those resources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @hono/node-server&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When using @hono/node-server&amp;#39;s static file serving together with route-based middleware protections (e.g. protecting `/admin/*`), inconsistent URL decoding can allow protected static resources to be accessed without authorization.&lt;/p&gt;
&lt;p&gt;In particular, paths containing encoded slashes (`%2F`) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middleware does not run but the static file is still served.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The routing layer and the node-server static handler normalize request paths differently. The router preserves `%2F` as a literal string when matching routes, while the static handler decodes `%2F` into `/` before resolving the filesystem path.&lt;/p&gt;
&lt;p&gt;Example request:&lt;/p&gt;
&lt;p&gt;- `/admin%2Fsecret.html`&lt;/p&gt;
&lt;p&gt;This may:
- fail to match middleware intended for `/admin/*`, but
- still be resolved by the static handler as `/admin/secret.html` under the configured static root.&lt;/p&gt;
&lt;p&gt;This does not allow access outside the configured static root and is not a path traversal vulnerability.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An unauthenticated attacker could bypass route-based authorization protections for protected static resources by supplying paths containing encoded slashes.&lt;/p&gt;
&lt;p&gt;Applications relying solely on route-based middleware to protect static subpaths under the same static root may have exposed those resources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wc8c-qw6v-h7f6</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1007 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1007</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1007</guid>
    </item>
  </channel>
</rss>
