<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:22:31 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-276625</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276625</link>
      <description>EUVD-2026-276625</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276625</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33131</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33131</link>
      <description>&lt;p&gt;H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which extends FastURL) which allows middleware bypass. When event.url, event.url.hostname, or event.url._url is accessed, such as in a logging middleware, the _url getter constructs a URL from untrusted data, including the user-controlled Host header. Because H3&amp;#39;s router resolves the route handler before middleware runs, an attacker can supply a crafted Host header (e.g., Host: localhost:3000/abchehe?) to make the middleware path check fail while the route handler still matches, effectively bypassing authentication or authorization middleware. This affects any application built on H3 (including Nitro/Nuxt) that accesses event.url properties in middleware guarding sensitive routes. The issue requires an immediate fix to prevent FastURL.href from being constructed with unsanitized, attacker-controlled input. Version 2.0.1-rc.15 contains a patch for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which extends FastURL) which allows middleware bypass. When event.url, event.url.hostname, or event.url._url is accessed, such as in a logging middleware, the _url getter constructs a URL from untrusted data, including the user-controlled Host header. Because H3&amp;#39;s router resolves the route handler before middleware runs, an attacker can supply a crafted Host header (e.g., Host: localhost:3000/abchehe?) to make the middleware path check fail while the route handler still matches, effectively bypassing authentication or authorization middleware. This affects any application built on H3 (including Nitro/Nuxt) that accesses event.url properties in middleware guarding sensitive routes. The issue requires an immediate fix to prevent FastURL.href from being constructed with unsanitized, attacker-controlled input. Version 2.0.1-rc.15 contains a patch for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33131</guid>
    </item>
    <item>
      <title>GHSA-3vj8-jmxq-cgj5 — h3 has a middleware bypass with one gadget</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3vj8-jmxq-cgj5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: h3&lt;/p&gt;
&lt;p&gt;# H3 NodeRequestUrl bugs&lt;/p&gt;
&lt;p&gt;Vulnerable pieces of code : 
```js
import { H3, serve, defineHandler, getQuery, getHeaders, readBody, defineNodeHandler } from &amp;#34;h3&amp;#34;;
let app = new H3()&lt;/p&gt;
&lt;p&gt;const internalOnly = defineHandler((event, next) =&amp;gt; {
  const token = event.headers.get(&amp;#34;x-internal-key&amp;#34;);&lt;/p&gt;
&lt;p&gt;if (token !== &amp;#34;SUPERRANDOMCANNOTBELEAKED&amp;#34;) {
    return new Response(&amp;#34;Forbidden&amp;#34;, { status: 403 });
  }&lt;/p&gt;
&lt;p&gt;return next();
});
const logger = defineHandler((event, next) =&amp;gt; {
    console.log(&amp;#34;Logging : &amp;#34; +  event.url.hostname)
    return next() 
})
app.use(logger);
app.use(&amp;#34;/internal/run&amp;#34;, internalOnly);&lt;/p&gt;
&lt;p&gt;app.get(&amp;#34;/internal/run&amp;#34;, () =&amp;gt; {
  return &amp;#34;Internal OK&amp;#34;;
});&lt;/p&gt;
&lt;p&gt;serve(app, { port: 3001 });
```&lt;/p&gt;
&lt;p&gt;The middleware is super safe now with just a logger and a middleware to block internal access.
But there&amp;#39;s one problems here at the logger .
When it log out the ```event.url``` or ```event.url.hostname``` or ```event.url._url```&lt;/p&gt;
&lt;p&gt;It will lead to trigger one specials method&lt;/p&gt;
&lt;p&gt;```js 
// _url.mjs FastURL
get _url() {
    if (this.#url) return this.#url;
    this.#url = new NativeURL(this.href);
    this.#href = void 0;
    this.#protocol = void 0;
    this.#host = void 0;
    this.#pathname = void 0;
    this.#search = void 0;
    this.#searchParams = void 0;
    this.#pos = void 0;
    return this.#url;
}
```&lt;/p&gt;
&lt;p&gt;The `NodeRequestUrl` is extends from `FastURL` so when we just access ```.url``` or trying to dump all data of this class . This function will be triggered !!&lt;/p&gt;
&lt;p&gt;And as debugging , the `this.#…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: h3&lt;/p&gt;
&lt;p&gt;# H3 NodeRequestUrl bugs&lt;/p&gt;
&lt;p&gt;Vulnerable pieces of code : 
```js
import { H3, serve, defineHandler, getQuery, getHeaders, readBody, defineNodeHandler } from &amp;#34;h3&amp;#34;;
let app = new H3()&lt;/p&gt;
&lt;p&gt;const internalOnly = defineHandler((event, next) =&amp;gt; {
  const token = event.headers.get(&amp;#34;x-internal-key&amp;#34;);&lt;/p&gt;
&lt;p&gt;if (token !== &amp;#34;SUPERRANDOMCANNOTBELEAKED&amp;#34;) {
    return new Response(&amp;#34;Forbidden&amp;#34;, { status: 403 });
  }&lt;/p&gt;
&lt;p&gt;return next();
});
const logger = defineHandler((event, next) =&amp;gt; {
    console.log(&amp;#34;Logging : &amp;#34; +  event.url.hostname)
    return next() 
})
app.use(logger);
app.use(&amp;#34;/internal/run&amp;#34;, internalOnly);&lt;/p&gt;
&lt;p&gt;app.get(&amp;#34;/internal/run&amp;#34;, () =&amp;gt; {
  return &amp;#34;Internal OK&amp;#34;;
});&lt;/p&gt;
&lt;p&gt;serve(app, { port: 3001 });
```&lt;/p&gt;
&lt;p&gt;The middleware is super safe now with just a logger and a middleware to block internal access.
But there&amp;#39;s one problems here at the logger .
When it log out the ```event.url``` or ```event.url.hostname``` or ```event.url._url```&lt;/p&gt;
&lt;p&gt;It will lead to trigger one specials method&lt;/p&gt;
&lt;p&gt;```js 
// _url.mjs FastURL
get _url() {
    if (this.#url) return this.#url;
    this.#url = new NativeURL(this.href);
    this.#href = void 0;
    this.#protocol = void 0;
    this.#host = void 0;
    this.#pathname = void 0;
    this.#search = void 0;
    this.#searchParams = void 0;
    this.#pos = void 0;
    return this.#url;
}
```&lt;/p&gt;
&lt;p&gt;The `NodeRequestUrl` is extends from `FastURL` so when we just access ```.url``` or trying to dump all data of this class . This function will be triggered !!&lt;/p&gt;
&lt;p&gt;And as debugging , the `this.#…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3vj8-jmxq-cgj5</guid>
    </item>
  </channel>
</rss>
