<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:53:05 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-01641</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-01641</link>
      <description>bdu:2025-01641</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-01641</guid>
    </item>
    <item>
      <title>BREW-vite-CVE-2025-24010 — Websites were able to send any requests to the development server and read the response in vite</title>
      <link>https://cve.radiocsirt.org/vuln/brew-vite-cve-2025-24010</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: vite&lt;/p&gt;
&lt;p&gt;### Summary
Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!WARNING]
&amp;gt; This vulnerability even applies to users that only run the Vite dev server on the local machine and does not expose the dev server to the network.&lt;/p&gt;
&lt;p&gt;### Upgrade Path
Users that does not match either of the following conditions should be able to upgrade to a newer version of Vite that fixes the vulnerability without any additional configuration.&lt;/p&gt;
&lt;p&gt;- Using the backend integration feature
- Using a reverse proxy in front of Vite
- Accessing the development server via a domain other than `localhost` or `*.localhost`
- Using a plugin / framework that connects to the WebSocket server on their own from the browser&lt;/p&gt;
&lt;p&gt;#### Using the backend integration feature
If you are using the backend integration feature and not setting [`server.origin`](https://vite.dev/config/server-options.html#server-origin), you need to add the origin of the backend server to the [`server.cors.origin`](https://github.com/expressjs/cors#configuration-options) option. Make sure to set a specific origin rather than `*`, otherwise any origin can access your development server.&lt;/p&gt;
&lt;p&gt;#### Using a reverse proxy in front of Vite
If you are using a reverse proxy in front of Vite and sending requests to Vite with a hostname other than `localhost` or `*.localhost`, you need to add the hostname to the new [`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: vite&lt;/p&gt;
&lt;p&gt;### Summary
Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!WARNING]
&amp;gt; This vulnerability even applies to users that only run the Vite dev server on the local machine and does not expose the dev server to the network.&lt;/p&gt;
&lt;p&gt;### Upgrade Path
Users that does not match either of the following conditions should be able to upgrade to a newer version of Vite that fixes the vulnerability without any additional configuration.&lt;/p&gt;
&lt;p&gt;- Using the backend integration feature
- Using a reverse proxy in front of Vite
- Accessing the development server via a domain other than `localhost` or `*.localhost`
- Using a plugin / framework that connects to the WebSocket server on their own from the browser&lt;/p&gt;
&lt;p&gt;#### Using the backend integration feature
If you are using the backend integration feature and not setting [`server.origin`](https://vite.dev/config/server-options.html#server-origin), you need to add the origin of the backend server to the [`server.cors.origin`](https://github.com/expressjs/cors#configuration-options) option. Make sure to set a specific origin rather than `*`, otherwise any origin can access your development server.&lt;/p&gt;
&lt;p&gt;#### Using a reverse proxy in front of Vite
If you are using a reverse proxy in front of Vite and sending requests to Vite with a hostname other than `localhost` or `*.localhost`, you need to add the hostname to the new [`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-vite-cve-2025-24010</guid>
    </item>
    <item>
      <title>EUVD-2026-211156</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-211156</link>
      <description>EUVD-2026-211156</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-211156</guid>
    </item>
    <item>
      <title>fkie_cve-2025-24010</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-24010</link>
      <description>&lt;p&gt;Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-24010</guid>
    </item>
    <item>
      <title>GHSA-vg6x-rcgg-rjx6 — Websites were able to send any requests to the development server and read the response in vite</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vg6x-rcgg-rjx6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vite&lt;/p&gt;
&lt;p&gt;### Summary
Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!WARNING]
&amp;gt; This vulnerability even applies to users that only run the Vite dev server on the local machine and does not expose the dev server to the network.&lt;/p&gt;
&lt;p&gt;### Upgrade Path
Users that does not match either of the following conditions should be able to upgrade to a newer version of Vite that fixes the vulnerability without any additional configuration.&lt;/p&gt;
&lt;p&gt;- Using the backend integration feature
- Using a reverse proxy in front of Vite
- Accessing the development server via a domain other than `localhost` or `*.localhost`
- Using a plugin / framework that connects to the WebSocket server on their own from the browser&lt;/p&gt;
&lt;p&gt;#### Using the backend integration feature
If you are using the backend integration feature and not setting [`server.origin`](https://vite.dev/config/server-options.html#server-origin), you need to add the origin of the backend server to the [`server.cors.origin`](https://github.com/expressjs/cors#configuration-options) option. Make sure to set a specific origin rather than `*`, otherwise any origin can access your development server.&lt;/p&gt;
&lt;p&gt;#### Using a reverse proxy in front of Vite
If you are using a reverse proxy in front of Vite and sending requests to Vite with a hostname other than `localhost` or `*.localhost`, you need to add the hostname to the new [`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vite&lt;/p&gt;
&lt;p&gt;### Summary
Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!WARNING]
&amp;gt; This vulnerability even applies to users that only run the Vite dev server on the local machine and does not expose the dev server to the network.&lt;/p&gt;
&lt;p&gt;### Upgrade Path
Users that does not match either of the following conditions should be able to upgrade to a newer version of Vite that fixes the vulnerability without any additional configuration.&lt;/p&gt;
&lt;p&gt;- Using the backend integration feature
- Using a reverse proxy in front of Vite
- Accessing the development server via a domain other than `localhost` or `*.localhost`
- Using a plugin / framework that connects to the WebSocket server on their own from the browser&lt;/p&gt;
&lt;p&gt;#### Using the backend integration feature
If you are using the backend integration feature and not setting [`server.origin`](https://vite.dev/config/server-options.html#server-origin), you need to add the origin of the backend server to the [`server.cors.origin`](https://github.com/expressjs/cors#configuration-options) option. Make sure to set a specific origin rather than `*`, otherwise any origin can access your development server.&lt;/p&gt;
&lt;p&gt;#### Using a reverse proxy in front of Vite
If you are using a reverse proxy in front of Vite and sending requests to Vite with a hostname other than `localhost` or `*.localhost`, you need to add the hostname to the new [`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vg6x-rcgg-rjx6</guid>
    </item>
  </channel>
</rss>
