<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 06:40:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277892</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277892</link>
      <description>EUVD-2026-277892</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277892</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33661</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33661</link>
      <description>&lt;p&gt;Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `verify_wechat_sign()` function in `src/Functions.php` unconditionally skips all signature verification when the PSR-7 request reports `localhost` as the host. An attacker can exploit this by sending a crafted HTTP request to the WeChat Pay callback endpoint with a `Host: localhost` header, bypassing the RSA signature check entirely. This allows forging fake WeChat Pay payment success notifications, potentially causing applications to mark orders as paid without actual payment. Version 3.7.20 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `verify_wechat_sign()` function in `src/Functions.php` unconditionally skips all signature verification when the PSR-7 request reports `localhost` as the host. An attacker can exploit this by sending a crafted HTTP request to the WeChat Pay callback endpoint with a `Host: localhost` header, bypassing the RSA signature check entirely. This allows forging fake WeChat Pay payment success notifications, potentially causing applications to mark orders as paid without actual payment. Version 3.7.20 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33661</guid>
    </item>
    <item>
      <title>GHSA-q938-ghwv-8gvc — WeChat Pay callback signature verification bypassed when Host header is localhost</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q938-ghwv-8gvc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: yansongda/pay&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `verify_wechat_sign()` function in `src/Functions.php` unconditionally **skips all signature verification** when the PSR-7 request reports `localhost` as the host. An attacker can exploit this by sending a crafted HTTP request to the WeChat Pay callback endpoint with a `Host: localhost` header, bypassing the RSA signature check entirely.&lt;/p&gt;
&lt;p&gt;This allows forging fake WeChat Pay payment success notifications, potentially causing applications to mark orders as paid without actual payment.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`src/Functions.php` lines 243-246:**
```php
function verify_wechat_sign(ResponseInterface|ServerRequestInterface $message, array $params): void
{
    // BYPASS: Returns without any signature check if Host header is localhost
    if ($message instanceof ServerRequestInterface &amp;amp;&amp;amp; &amp;#39;localhost&amp;#39; === $message-&amp;gt;getUri()-&amp;gt;getHost()) {
        return;  // No signature verified!
    }&lt;/p&gt;
&lt;p&gt;// ... openssl_verify() only reached when Host != localhost
    $wechatSerial = $message-&amp;gt;getHeaderLine(&amp;#39;Wechatpay-Serial&amp;#39;);
    $sign = $message-&amp;gt;getHeaderLine(&amp;#39;Wechatpay-Signature&amp;#39;);
    $result = 1 === openssl_verify($content, base64_decode($sign), $public, &amp;#39;sha256WithRSAEncryption&amp;#39;);
}
```&lt;/p&gt;
&lt;p&gt;In PSR-7 implementations (Nyholm, Guzzle PSR-7, etc.), `$request-&amp;gt;getUri()-&amp;gt;getHost()` reads the `Host` HTTP header, which is fully attacker-controlled.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```bash
curl -X POST https://merchant.example.com/payment/wechat/callback \
  -H &amp;#34;Host: localhost&amp;#34; \
  -H &amp;#34;Content-Type…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: yansongda/pay&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `verify_wechat_sign()` function in `src/Functions.php` unconditionally **skips all signature verification** when the PSR-7 request reports `localhost` as the host. An attacker can exploit this by sending a crafted HTTP request to the WeChat Pay callback endpoint with a `Host: localhost` header, bypassing the RSA signature check entirely.&lt;/p&gt;
&lt;p&gt;This allows forging fake WeChat Pay payment success notifications, potentially causing applications to mark orders as paid without actual payment.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`src/Functions.php` lines 243-246:**
```php
function verify_wechat_sign(ResponseInterface|ServerRequestInterface $message, array $params): void
{
    // BYPASS: Returns without any signature check if Host header is localhost
    if ($message instanceof ServerRequestInterface &amp;amp;&amp;amp; &amp;#39;localhost&amp;#39; === $message-&amp;gt;getUri()-&amp;gt;getHost()) {
        return;  // No signature verified!
    }&lt;/p&gt;
&lt;p&gt;// ... openssl_verify() only reached when Host != localhost
    $wechatSerial = $message-&amp;gt;getHeaderLine(&amp;#39;Wechatpay-Serial&amp;#39;);
    $sign = $message-&amp;gt;getHeaderLine(&amp;#39;Wechatpay-Signature&amp;#39;);
    $result = 1 === openssl_verify($content, base64_decode($sign), $public, &amp;#39;sha256WithRSAEncryption&amp;#39;);
}
```&lt;/p&gt;
&lt;p&gt;In PSR-7 implementations (Nyholm, Guzzle PSR-7, etc.), `$request-&amp;gt;getUri()-&amp;gt;getHost()` reads the `Host` HTTP header, which is fully attacker-controlled.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```bash
curl -X POST https://merchant.example.com/payment/wechat/callback \
  -H &amp;#34;Host: localhost&amp;#34; \
  -H &amp;#34;Content-Type…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q938-ghwv-8gvc</guid>
    </item>
  </channel>
</rss>
