<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:21:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-262950</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262950</link>
      <description>EUVD-2026-262950</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262950</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66202</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66202</link>
      <description>&lt;p&gt;Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks in Astro middleware, granting unauthorized access to protected routes. While the original CVE-2025-64765 was fixed in v5.15.8, the fix is insufficient as it only decodes once. By using double-encoded URLs, attackers can still bypass authentication and access any route protected by middleware pathname checks. This issue is fixed in version 5.15.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks in Astro middleware, granting unauthorized access to protected routes. While the original CVE-2025-64765 was fixed in v5.15.8, the fix is insufficient as it only decodes once. By using double-encoded URLs, attackers can still bypass authentication and access any route protected by middleware pathname checks. This issue is fixed in version 5.15.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66202</guid>
    </item>
    <item>
      <title>GHSA-whqg-ppgf-wp8c — Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-whqg-ppgf-wp8c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: astro&lt;/p&gt;
&lt;p&gt;# Authentication Bypass via Double URL Encoding in Astro
## Bypass for CVE-2025-64765 / GHSA-ggxq-hp9w-j794&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A **double URL encoding bypass** allows any unauthenticated attacker to bypass path-based authentication checks in Astro middleware, granting unauthorized access to protected routes. While the original CVE-2025-64765 (single URL encoding) was fixed in v5.15.8, the fix is insufficient as it only decodes once. By using double-encoded URLs like `/%2561dmin` instead of `/%61dmin`, attackers can still bypass authentication and access protected resources such as `/admin`, `/api/internal`, or any route protected by middleware pathname checks.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;A more secure fix is just decoding once, then if the request has a %xx format, return a 400 error by using something like :&lt;/p&gt;
&lt;p&gt;```
if (containsEncodedCharacters(pathname)) {
            // Multi-level encoding detected - reject request
            return new Response(
                &amp;#39;Bad Request: Multi-level URL encoding is not allowed&amp;#39;,
                {
                    status: 400,
                    headers: { &amp;#39;Content-Type&amp;#39;: &amp;#39;text/plain&amp;#39; }
                }
            );
        }
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: astro&lt;/p&gt;
&lt;p&gt;# Authentication Bypass via Double URL Encoding in Astro
## Bypass for CVE-2025-64765 / GHSA-ggxq-hp9w-j794&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A **double URL encoding bypass** allows any unauthenticated attacker to bypass path-based authentication checks in Astro middleware, granting unauthorized access to protected routes. While the original CVE-2025-64765 (single URL encoding) was fixed in v5.15.8, the fix is insufficient as it only decodes once. By using double-encoded URLs like `/%2561dmin` instead of `/%61dmin`, attackers can still bypass authentication and access protected resources such as `/admin`, `/api/internal`, or any route protected by middleware pathname checks.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;A more secure fix is just decoding once, then if the request has a %xx format, return a 400 error by using something like :&lt;/p&gt;
&lt;p&gt;```
if (containsEncodedCharacters(pathname)) {
            // Multi-level encoding detected - reject request
            return new Response(
                &amp;#39;Bad Request: Multi-level URL encoding is not allowed&amp;#39;,
                {
                    status: 400,
                    headers: { &amp;#39;Content-Type&amp;#39;: &amp;#39;text/plain&amp;#39; }
                }
            );
        }
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-whqg-ppgf-wp8c</guid>
    </item>
  </channel>
</rss>
