<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:04:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05651</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05651</link>
      <description>bdu:2026-05651</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05651</guid>
    </item>
    <item>
      <title>EUVD-2026-291385</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291385</link>
      <description>EUVD-2026-291385</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291385</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33807</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33807</link>
      <description>&lt;p&gt;@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is registered with a prefix that matches a middleware path, the middleware path is prefixed a second time, causing it to never match incoming requests. This results in complete bypass of Express middleware security controls, including authentication, authorization, and rate limiting, for all routes defined within affected child plugin scopes. No special configuration or request crafting is required.&lt;/p&gt;
&lt;p&gt;Upgrade to @fastify/express v4.0.5 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is registered with a prefix that matches a middleware path, the middleware path is prefixed a second time, causing it to never match incoming requests. This results in complete bypass of Express middleware security controls, including authentication, authorization, and rate limiting, for all routes defined within affected child plugin scopes. No special configuration or request crafting is required.&lt;/p&gt;
&lt;p&gt;Upgrade to @fastify/express v4.0.5 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33807</guid>
    </item>
    <item>
      <title>GHSA-hrwm-hgmj-7p9c — @fastify/express's middleware path doubling causes authentication bypass in child plugin scopes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hrwm-hgmj-7p9c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fastify/express&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`@fastify/express` v4.0.4 contains a path handling bug in the `onRegister` function that causes middleware paths to be doubled when inherited by child plugins. This results in complete bypass of Express middleware security controls for all routes defined within child plugin scopes that share a prefix with parent-scoped middleware. No special configuration is required — this affects the default Fastify configuration.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in the `onRegister` function at `index.js` lines 92-101. When a child plugin is registered with a prefix, the `onRegister` hook copies middleware from the parent scope and re-registers it using `instance.use(...middleware)`. However, the middleware paths stored in `kMiddlewares` are already prefixed from their original registration.&lt;/p&gt;
&lt;p&gt;The call flow demonstrates the problem:
1. Parent scope registers middleware: `app.use(&amp;#39;/admin&amp;#39;, authFn)` — `use()` calculates path as `&amp;#39;&amp;#39; + &amp;#39;/admin&amp;#39; = &amp;#39;/admin&amp;#39;` — stores `[&amp;#39;/admin&amp;#39;, authFn]` in `kMiddlewares`
2. Child plugin registers with `{ prefix: &amp;#39;/admin&amp;#39; }` — triggers `onRegister(instance)`
3. `onRegister` copies parent middleware and calls `instance.use(&amp;#39;/admin&amp;#39;, authFn)` on child
4. Child&amp;#39;s `use()` function calculates path as `&amp;#39;/admin&amp;#39; + &amp;#39;/admin&amp;#39; = &amp;#39;/admin/admin&amp;#39;` — registers middleware with doubled path
5. Routes in child scope use the child&amp;#39;s Express instance, where middleware is registered under the incorrect path `/admin/admin`
6. Requests to `/admin/secret` don&amp;#39;t match…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fastify/express&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`@fastify/express` v4.0.4 contains a path handling bug in the `onRegister` function that causes middleware paths to be doubled when inherited by child plugins. This results in complete bypass of Express middleware security controls for all routes defined within child plugin scopes that share a prefix with parent-scoped middleware. No special configuration is required — this affects the default Fastify configuration.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in the `onRegister` function at `index.js` lines 92-101. When a child plugin is registered with a prefix, the `onRegister` hook copies middleware from the parent scope and re-registers it using `instance.use(...middleware)`. However, the middleware paths stored in `kMiddlewares` are already prefixed from their original registration.&lt;/p&gt;
&lt;p&gt;The call flow demonstrates the problem:
1. Parent scope registers middleware: `app.use(&amp;#39;/admin&amp;#39;, authFn)` — `use()` calculates path as `&amp;#39;&amp;#39; + &amp;#39;/admin&amp;#39; = &amp;#39;/admin&amp;#39;` — stores `[&amp;#39;/admin&amp;#39;, authFn]` in `kMiddlewares`
2. Child plugin registers with `{ prefix: &amp;#39;/admin&amp;#39; }` — triggers `onRegister(instance)`
3. `onRegister` copies parent middleware and calls `instance.use(&amp;#39;/admin&amp;#39;, authFn)` on child
4. Child&amp;#39;s `use()` function calculates path as `&amp;#39;/admin&amp;#39; + &amp;#39;/admin&amp;#39; = &amp;#39;/admin/admin&amp;#39;` — registers middleware with doubled path
5. Routes in child scope use the child&amp;#39;s Express instance, where middleware is registered under the incorrect path `/admin/admin`
6. Requests to `/admin/secret` don&amp;#39;t match…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hrwm-hgmj-7p9c</guid>
    </item>
  </channel>
</rss>
