<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 18:53:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-239367</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-239367</link>
      <description>EUVD-2026-239367</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-239367</guid>
    </item>
    <item>
      <title>fkie_cve-2025-43855</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-43855</link>
      <description>&lt;p&gt;tRPC allows users to build &amp;amp; consume fully typesafe APIs without schemas or code generation. In versions starting from 11.0.0 to before 11.1.1, an unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any unauthenticated user to crash a tRPC 11 WebSocket server. Any tRPC 11 server with WebSocket enabled with a createContext method set is vulnerable. This issue has been patched in version 11.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tRPC allows users to build &amp;amp; consume fully typesafe APIs without schemas or code generation. In versions starting from 11.0.0 to before 11.1.1, an unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any unauthenticated user to crash a tRPC 11 WebSocket server. Any tRPC 11 server with WebSocket enabled with a createContext method set is vulnerable. This issue has been patched in version 11.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-43855</guid>
    </item>
    <item>
      <title>GHSA-pj3v-9cm8-gvj8 — tRPC 11 WebSocket DoS Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pj3v-9cm8-gvj8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @trpc/server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any unauthenticated user to crash a tRPC 11 WebSocket server.&lt;/p&gt;
&lt;p&gt;### Details
Any tRPC 11 server with WebSocket enabled with a `createContext` method set is vulnerable. Here is an example:&lt;/p&gt;
&lt;p&gt;https://github.com/user-attachments/assets/ce1b2d32-6103-4e54-8446-51535b293b05&lt;/p&gt;
&lt;p&gt;I have a working reproduction here if you would like to test: https://github.com/lukechilds/trpc-vuln-reproduction&lt;/p&gt;
&lt;p&gt;The connectionParams logic introduced in https://github.com/trpc/trpc/pull/5839 does not safely handle invalid connectionParams objects. During validation if the object does not match an expected shape an error will be thrown:&lt;/p&gt;
&lt;p&gt;https://github.com/trpc/trpc/blob/8cef54eaf95d8abc8484fe1d454b6620eeb57f2f/packages/server/src/unstable-core-do-not-import/http/parseConnectionParams.ts#L27-L33&lt;/p&gt;
&lt;p&gt;This is called during WebSocket connection setup inside `createCtxPromise()` here:&lt;/p&gt;
&lt;p&gt;https://github.com/trpc/trpc/blob/8cef54eaf95d8abc8484fe1d454b6620eeb57f2f/packages/server/src/adapters/ws.ts#L435&lt;/p&gt;
&lt;p&gt;`createCtxPromise` has handling to catch any errors and pass them up to the `opts.onError` handler:&lt;/p&gt;
&lt;p&gt;https://github.com/trpc/trpc/blob/8cef54eaf95d8abc8484fe1d454b6620eeb57f2f/packages/server/src/adapters/ws.ts#L144-L173&lt;/p&gt;
&lt;p&gt;However the error handler then rethrows the error:&lt;/p&gt;
&lt;p&gt;https://github.com/trpc/trpc/blob/8cef54eaf95d8abc8484fe1d454b6620eeb57f2f/packages/server/src/adapters/ws.ts#L171&lt;/p&gt;
&lt;p&gt;S…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @trpc/server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any unauthenticated user to crash a tRPC 11 WebSocket server.&lt;/p&gt;
&lt;p&gt;### Details
Any tRPC 11 server with WebSocket enabled with a `createContext` method set is vulnerable. Here is an example:&lt;/p&gt;
&lt;p&gt;https://github.com/user-attachments/assets/ce1b2d32-6103-4e54-8446-51535b293b05&lt;/p&gt;
&lt;p&gt;I have a working reproduction here if you would like to test: https://github.com/lukechilds/trpc-vuln-reproduction&lt;/p&gt;
&lt;p&gt;The connectionParams logic introduced in https://github.com/trpc/trpc/pull/5839 does not safely handle invalid connectionParams objects. During validation if the object does not match an expected shape an error will be thrown:&lt;/p&gt;
&lt;p&gt;https://github.com/trpc/trpc/blob/8cef54eaf95d8abc8484fe1d454b6620eeb57f2f/packages/server/src/unstable-core-do-not-import/http/parseConnectionParams.ts#L27-L33&lt;/p&gt;
&lt;p&gt;This is called during WebSocket connection setup inside `createCtxPromise()` here:&lt;/p&gt;
&lt;p&gt;https://github.com/trpc/trpc/blob/8cef54eaf95d8abc8484fe1d454b6620eeb57f2f/packages/server/src/adapters/ws.ts#L435&lt;/p&gt;
&lt;p&gt;`createCtxPromise` has handling to catch any errors and pass them up to the `opts.onError` handler:&lt;/p&gt;
&lt;p&gt;https://github.com/trpc/trpc/blob/8cef54eaf95d8abc8484fe1d454b6620eeb57f2f/packages/server/src/adapters/ws.ts#L144-L173&lt;/p&gt;
&lt;p&gt;However the error handler then rethrows the error:&lt;/p&gt;
&lt;p&gt;https://github.com/trpc/trpc/blob/8cef54eaf95d8abc8484fe1d454b6620eeb57f2f/packages/server/src/adapters/ws.ts#L171&lt;/p&gt;
&lt;p&gt;S…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pj3v-9cm8-gvj8</guid>
    </item>
  </channel>
</rss>
