<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 19:52:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-263813</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-263813</link>
      <description>EUVD-2026-263813</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-263813</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68130</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68130</link>
      <description>&lt;p&gt;tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`&amp;#39;s `formDataToObject` function, which is used by the Next.js App Router adapter. An attacker can pollute `Object.prototype` by submitting specially crafted FormData field names, potentially leading to authorization bypass, denial of service, or other security impacts. Note that this vulnerability is only present when using `experimental_caller` / `experimental_nextAppDirCaller`. Versions 10.45.3 and 11.8.0 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`&amp;#39;s `formDataToObject` function, which is used by the Next.js App Router adapter. An attacker can pollute `Object.prototype` by submitting specially crafted FormData field names, potentially leading to authorization bypass, denial of service, or other security impacts. Note that this vulnerability is only present when using `experimental_caller` / `experimental_nextAppDirCaller`. Versions 10.45.3 and 11.8.0 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68130</guid>
    </item>
    <item>
      <title>GHSA-43p4-m455-4f4j — tRPC has possible prototype pollution in `experimental_nextAppDirCaller`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-43p4-m455-4f4j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @trpc/server&lt;/p&gt;
&lt;p&gt;&amp;gt; Note that this vulnerability is only present when using `experimental_caller` / `experimental_nextAppDirCaller`.&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A Prototype Pollution vulnerability exists in `@trpc/server`&amp;#39;s `formDataToObject` function, which is used by the Next.js App Router adapter. An attacker can pollute `Object.prototype` by submitting specially crafted FormData field names, potentially leading to authorization bypass, denial of service, or other security impacts.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- **Package:** `@trpc/server`
- **Affected Versions:** &amp;gt;=10.27.0
- **Vulnerable Component:** `formDataToObject()` in `src/unstable-core-do-not-import/http/formDataToObject.ts`&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;The `set()` function in `formDataToObject.ts` recursively processes FormData field names containing bracket/dot notation (e.g., `user[name]`, `user.address.city`) to create nested objects. However, it does **not** validate or sanitize dangerous keys like `__proto__`, `constructor`, or `prototype`.&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;```typescript
// packages/server/src/unstable-core-do-not-import/http/formDataToObject.ts
function set(obj, path, value) {
  if (path.length &amp;gt; 1) {
    const newPath = [...path];
    const key = newPath.shift();  // ← No validation of dangerous keys
    const nextKey = newPath[0];&lt;/p&gt;
&lt;p&gt;if (!obj[key]) {  // ← Accesses obj[&amp;#34;__proto__&amp;#34;] which returns Object.prototype
      obj[key] = isNumberString(nextKey) ? [] : {};
    }
    
    set(obj[key], newPath, value);  // ← Recursiv…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @trpc/server&lt;/p&gt;
&lt;p&gt;&amp;gt; Note that this vulnerability is only present when using `experimental_caller` / `experimental_nextAppDirCaller`.&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A Prototype Pollution vulnerability exists in `@trpc/server`&amp;#39;s `formDataToObject` function, which is used by the Next.js App Router adapter. An attacker can pollute `Object.prototype` by submitting specially crafted FormData field names, potentially leading to authorization bypass, denial of service, or other security impacts.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- **Package:** `@trpc/server`
- **Affected Versions:** &amp;gt;=10.27.0
- **Vulnerable Component:** `formDataToObject()` in `src/unstable-core-do-not-import/http/formDataToObject.ts`&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;The `set()` function in `formDataToObject.ts` recursively processes FormData field names containing bracket/dot notation (e.g., `user[name]`, `user.address.city`) to create nested objects. However, it does **not** validate or sanitize dangerous keys like `__proto__`, `constructor`, or `prototype`.&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;```typescript
// packages/server/src/unstable-core-do-not-import/http/formDataToObject.ts
function set(obj, path, value) {
  if (path.length &amp;gt; 1) {
    const newPath = [...path];
    const key = newPath.shift();  // ← No validation of dangerous keys
    const nextKey = newPath[0];&lt;/p&gt;
&lt;p&gt;if (!obj[key]) {  // ← Accesses obj[&amp;#34;__proto__&amp;#34;] which returns Object.prototype
      obj[key] = isNumberString(nextKey) ? [] : {};
    }
    
    set(obj[key], newPath, value);  // ← Recursiv…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-43p4-m455-4f4j</guid>
    </item>
  </channel>
</rss>
