<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 12:43:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-227559</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-227559</link>
      <description>EUVD-2026-227559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-227559</guid>
    </item>
    <item>
      <title>fkie_cve-2025-31481</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-31481</link>
      <description>&lt;p&gt;API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-31481</guid>
    </item>
    <item>
      <title>GHSA-cg3c-245w-728m — GraphQL query operations security can be bypassed</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cg3c-245w-728m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: api-platform/graphql, Packagist: api-platform/core&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Using the Relay special `node` type you can bypass the configured security on an operation.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Here is an example of how to apply security configurations for the GraphQL operations:&lt;/p&gt;
&lt;p&gt;```php
#[ApiResource(
    security: &amp;#34;is_granted(&amp;#39;ROLE_USER&amp;#39;)&amp;#34;,
    operations: [ /* ... */ ],
    graphQlOperations: [
        new Query(security: &amp;#34;is_granted(&amp;#39;ROLE_USER&amp;#39;)&amp;#34;),
        //...
    ],
)]
class Book { /* ... */ }
```&lt;/p&gt;
&lt;p&gt;This indeed checks `is_granted(&amp;#39;ROLE_USER&amp;#39;)` as expected for a GraphQL query like the following:&lt;/p&gt;
&lt;p&gt;```php
‌query {
    book(id: &amp;#34;/books/1&amp;#34;) {
        title
    }
}
```&lt;/p&gt;
&lt;p&gt;But the security check can be bypassed by using the `node` field (that is available by default) on the root query type like that:&lt;/p&gt;
&lt;p&gt;```php
‌query {
    node(id: &amp;#34;/books/1&amp;#34;) {
        ... on Book {
            title
        }
    }
}
```&lt;/p&gt;
&lt;p&gt;This does not execute any security checks and can therefore be used to access any entity without restrictions by everyone that has access to the API.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Everyone using GraphQl with the `security` attribute. Not sure whereas this works with custom resolvers nor if this also applies on mutation.&lt;/p&gt;
&lt;p&gt;Patched at https://github.com/api-platform/core/commit/60747cc8c2fb855798c923b5537888f8d0969568&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: api-platform/graphql, Packagist: api-platform/core&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Using the Relay special `node` type you can bypass the configured security on an operation.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Here is an example of how to apply security configurations for the GraphQL operations:&lt;/p&gt;
&lt;p&gt;```php
#[ApiResource(
    security: &amp;#34;is_granted(&amp;#39;ROLE_USER&amp;#39;)&amp;#34;,
    operations: [ /* ... */ ],
    graphQlOperations: [
        new Query(security: &amp;#34;is_granted(&amp;#39;ROLE_USER&amp;#39;)&amp;#34;),
        //...
    ],
)]
class Book { /* ... */ }
```&lt;/p&gt;
&lt;p&gt;This indeed checks `is_granted(&amp;#39;ROLE_USER&amp;#39;)` as expected for a GraphQL query like the following:&lt;/p&gt;
&lt;p&gt;```php
‌query {
    book(id: &amp;#34;/books/1&amp;#34;) {
        title
    }
}
```&lt;/p&gt;
&lt;p&gt;But the security check can be bypassed by using the `node` field (that is available by default) on the root query type like that:&lt;/p&gt;
&lt;p&gt;```php
‌query {
    node(id: &amp;#34;/books/1&amp;#34;) {
        ... on Book {
            title
        }
    }
}
```&lt;/p&gt;
&lt;p&gt;This does not execute any security checks and can therefore be used to access any entity without restrictions by everyone that has access to the API.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Everyone using GraphQl with the `security` attribute. Not sure whereas this works with custom resolvers nor if this also applies on mutation.&lt;/p&gt;
&lt;p&gt;Patched at https://github.com/api-platform/core/commit/60747cc8c2fb855798c923b5537888f8d0969568&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cg3c-245w-728m</guid>
    </item>
  </channel>
</rss>
