<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 12:53:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-274650</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274650</link>
      <description>EUVD-2026-274650</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274650</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64166</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64166</link>
      <description>&lt;p&gt;Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability was identified. The issue arises from incorrect parsing of the Content-Type header in requests. Specifically, requests with Content-Type values such as application/x-www-form-urlencoded, multipart/form-data, or text/plain could be misinterpreted as application/json. This misinterpretation bypasses the preflight checks performed by the fetch() API, potentially allowing unauthorized actions to be performed on behalf of an authenticated user. This issue has been patched in version 16.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability was identified. The issue arises from incorrect parsing of the Content-Type header in requests. Specifically, requests with Content-Type values such as application/x-www-form-urlencoded, multipart/form-data, or text/plain could be misinterpreted as application/json. This misinterpretation bypasses the preflight checks performed by the fetch() API, potentially allowing unauthorized actions to be performed on behalf of an authenticated user. This issue has been patched in version 16.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64166</guid>
    </item>
    <item>
      <title>GHSA-v66j-6wwf-jc57 — Mercurius: Incorrect Content-Type parsing can lead to CSRF attack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v66j-6wwf-jc57</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mercurius&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A Cross-Site Request Forgery (CSRF) vulnerability was identified in Mercurius versions 16. The issue arises from incorrect parsing of the `Content-Type` header in requests. Specifically, requests with `Content-Type` values such as `application/x-www-form-urlencoded`, `multipart/form-data`, or `text/plain` could be misinterpreted as `application/json`. This misinterpretation bypasses the preflight checks performed by the `fetch()` API, potentially allowing unauthorized actions to be performed on behalf of an authenticated user.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker could exploit this vulnerability by crafting a malicious request with a `Content-Type` that Fastify incorrectly parses as `application/json`. When such a request is made from a different origin, it bypasses the Cross-Origin Resource Sharing (CORS) protections, leading to a potential CSRF attack. This could result in unauthorized actions being performed on behalf of an authenticated user without their consent.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;```javascript
// Server-side Fastify setup
const Fastify = require(&amp;#39;fastify&amp;#39;);
const mercurius = require(&amp;#39;mercurius&amp;#39;);&lt;/p&gt;
&lt;p&gt;const app = Fastify();
const schema = `
  type Query {
    hello(name: String): String
  }
`;&lt;/p&gt;
&lt;p&gt;const resolvers = {
  Query: {
    hello: (_, { name }) =&amp;gt; `Hello ${name || &amp;#39;World&amp;#39;}!`
  }
};&lt;/p&gt;
&lt;p&gt;app.register(mercurius, { schema, resolvers });&lt;/p&gt;
&lt;p&gt;app.listen(3000, () =&amp;gt; {
  console.log(&amp;#39;Server listening on http://localhost:3000&amp;#39;);
});
```&lt;/p&gt;
&lt;p&gt;```javascript
// Malicious cl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mercurius&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A Cross-Site Request Forgery (CSRF) vulnerability was identified in Mercurius versions 16. The issue arises from incorrect parsing of the `Content-Type` header in requests. Specifically, requests with `Content-Type` values such as `application/x-www-form-urlencoded`, `multipart/form-data`, or `text/plain` could be misinterpreted as `application/json`. This misinterpretation bypasses the preflight checks performed by the `fetch()` API, potentially allowing unauthorized actions to be performed on behalf of an authenticated user.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker could exploit this vulnerability by crafting a malicious request with a `Content-Type` that Fastify incorrectly parses as `application/json`. When such a request is made from a different origin, it bypasses the Cross-Origin Resource Sharing (CORS) protections, leading to a potential CSRF attack. This could result in unauthorized actions being performed on behalf of an authenticated user without their consent.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;```javascript
// Server-side Fastify setup
const Fastify = require(&amp;#39;fastify&amp;#39;);
const mercurius = require(&amp;#39;mercurius&amp;#39;);&lt;/p&gt;
&lt;p&gt;const app = Fastify();
const schema = `
  type Query {
    hello(name: String): String
  }
`;&lt;/p&gt;
&lt;p&gt;const resolvers = {
  Query: {
    hello: (_, { name }) =&amp;gt; `Hello ${name || &amp;#39;World&amp;#39;}!`
  }
};&lt;/p&gt;
&lt;p&gt;app.register(mercurius, { schema, resolvers });&lt;/p&gt;
&lt;p&gt;app.listen(3000, () =&amp;gt; {
  console.log(&amp;#39;Server listening on http://localhost:3000&amp;#39;);
});
```&lt;/p&gt;
&lt;p&gt;```javascript
// Malicious cl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v66j-6wwf-jc57</guid>
    </item>
  </channel>
</rss>
