<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 17:41:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-262992</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262992</link>
      <description>EUVD-2026-262992</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262992</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66456</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66456</link>
      <description>&lt;p&gt;Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due to the ordering of merging, there must be an any type that is set as a standalone guard, to allow for the `__proto__ prop` to be merged. When combined with GHSA-8vch-m3f4-q8jf this allows for a full RCE by an attacker. This issue is fixed in version 1.4.17. To workaround, remove the `__proto__ key` from body.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due to the ordering of merging, there must be an any type that is set as a standalone guard, to allow for the `__proto__ prop` to be merged. When combined with GHSA-8vch-m3f4-q8jf this allows for a full RCE by an attacker. This issue is fixed in version 1.4.17. To workaround, remove the `__proto__ key` from body.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66456</guid>
    </item>
    <item>
      <title>GHSA-hxj9-33pp-j2cc — Elysia vulnerable to prototype pollution with multiple standalone schema validation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hxj9-33pp-j2cc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: elysia&lt;/p&gt;
&lt;p&gt;Prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due to the ordering of merging, there must be an `any` type that is set as a `standalone` guard, to allow for the `__proto__` prop to be merged.&lt;/p&gt;
&lt;p&gt;When combined with GHSA-8vch-m3f4-q8jf this allows for a full RCE by an attacker.&lt;/p&gt;
&lt;p&gt;### Impact
Routes with more than 2 standalone schema validation, eg. zod&lt;/p&gt;
&lt;p&gt;Example vulnerable code:
```typescript
import { Elysia } from &amp;#34;elysia&amp;#34;
import * as z from &amp;#34;zod&amp;#34;&lt;/p&gt;
&lt;p&gt;const app = new Elysia()
	.guard({
		schema: &amp;#34;standalone&amp;#34;,
		body: z.object({
			data: z.any()
		})
	})
	.post(&amp;#34;/&amp;#34;, ({ body }) =&amp;gt; ({ body, win: {}.foo }), {
		body: z.object({
			data: z.object({
				messageId: z.string(&amp;#34;pollute-me&amp;#34;),
			})
		})
	})
```&lt;/p&gt;
&lt;p&gt;### Patches
Patched by 1.4.17 (https://github.com/elysiajs/elysia/pull/1564)&lt;/p&gt;
&lt;p&gt;Reference commit:
- https://github.com/elysiajs/elysia/pull/1564/commits/26935bf76ebc43b4a43d48b173fc853de43bb51e
- https://github.com/elysiajs/elysia/pull/1564/commits/3af978663e437dccc6c1a2a3aff4b74e1574849e&lt;/p&gt;
&lt;p&gt;### Workarounds
Remove `__proto__` key from body&lt;/p&gt;
&lt;p&gt;Example plugin for removing `__proto__` from body&lt;/p&gt;
&lt;p&gt;```typescript
new Elysia()
	.onTransform(({ body, headers }) =&amp;gt; {
		if (headers[&amp;#39;content-type&amp;#39;] === &amp;#39;application/json&amp;#39;)
			return JSON.parse(JSON.stringify(body), (k, v) =&amp;gt; {
				if (k === &amp;#39;__proto__&amp;#39;) return&lt;/p&gt;
&lt;p&gt;return v
			})
	})
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: elysia&lt;/p&gt;
&lt;p&gt;Prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due to the ordering of merging, there must be an `any` type that is set as a `standalone` guard, to allow for the `__proto__` prop to be merged.&lt;/p&gt;
&lt;p&gt;When combined with GHSA-8vch-m3f4-q8jf this allows for a full RCE by an attacker.&lt;/p&gt;
&lt;p&gt;### Impact
Routes with more than 2 standalone schema validation, eg. zod&lt;/p&gt;
&lt;p&gt;Example vulnerable code:
```typescript
import { Elysia } from &amp;#34;elysia&amp;#34;
import * as z from &amp;#34;zod&amp;#34;&lt;/p&gt;
&lt;p&gt;const app = new Elysia()
	.guard({
		schema: &amp;#34;standalone&amp;#34;,
		body: z.object({
			data: z.any()
		})
	})
	.post(&amp;#34;/&amp;#34;, ({ body }) =&amp;gt; ({ body, win: {}.foo }), {
		body: z.object({
			data: z.object({
				messageId: z.string(&amp;#34;pollute-me&amp;#34;),
			})
		})
	})
```&lt;/p&gt;
&lt;p&gt;### Patches
Patched by 1.4.17 (https://github.com/elysiajs/elysia/pull/1564)&lt;/p&gt;
&lt;p&gt;Reference commit:
- https://github.com/elysiajs/elysia/pull/1564/commits/26935bf76ebc43b4a43d48b173fc853de43bb51e
- https://github.com/elysiajs/elysia/pull/1564/commits/3af978663e437dccc6c1a2a3aff4b74e1574849e&lt;/p&gt;
&lt;p&gt;### Workarounds
Remove `__proto__` key from body&lt;/p&gt;
&lt;p&gt;Example plugin for removing `__proto__` from body&lt;/p&gt;
&lt;p&gt;```typescript
new Elysia()
	.onTransform(({ body, headers }) =&amp;gt; {
		if (headers[&amp;#39;content-type&amp;#39;] === &amp;#39;application/json&amp;#39;)
			return JSON.parse(JSON.stringify(body), (k, v) =&amp;gt; {
				if (k === &amp;#39;__proto__&amp;#39;) return&lt;/p&gt;
&lt;p&gt;return v
			})
	})
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hxj9-33pp-j2cc</guid>
    </item>
  </channel>
</rss>
