<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 02:18:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-293001</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-293001</link>
      <description>EUVD-2026-293001</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-293001</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41322</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41322</link>
      <description>&lt;p&gt;@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year cache lifetime instead of 412 in some cases. This has the effect that all subsequent requests to that file, regardless of if-match header will be served a 5xx error instead of the file until the cache expires. This vulnerability is fixed in 10.0.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year cache lifetime instead of 412 in some cases. This has the effect that all subsequent requests to that file, regardless of if-match header will be served a 5xx error instead of the file until the cache expires. This vulnerability is fixed in 10.0.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41322</guid>
    </item>
    <item>
      <title>GHSA-c57f-mm3j-27q9 — Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c57f-mm3j-27q9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @astrojs/node&lt;/p&gt;
&lt;p&gt;### Summary
Requesting a static JS/CSS resource from the `_astro` path with an incorrect or malformed `if-match` header returns a `500` error with a one-year cache lifetime instead of `412` in some cases. As a result, all subsequent requests to that file — regardless of the `if-match` header — will be served a 5xx error instead of the file until the cache expires.&lt;/p&gt;
&lt;p&gt;Sending an incorrect or malformed `if-match` header should always return a `412` error without any cache headers, which is not the current behavior.&lt;/p&gt;
&lt;p&gt;### Affected Versions
- `astro@5.14.1`
- `@astrojs/node@9.4.4`&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;Run the following command:&lt;/p&gt;
&lt;p&gt;```
curl -s -o /dev/null -D - &amp;lt;host location&amp;gt;/_astro/_slug_.UTbyeVfw.css -H &amp;#34;if-match: xxx&amp;#34;
```&lt;/p&gt;
&lt;p&gt;If a 5xx error is not returned, inspect the resources via the browser&amp;#39;s web inspector and select another CSS/JS file to request until a 5xx error is returned. The behavior generally defaults to a 5xx response. Note that all static files are immutable, so the cache must be purged or disabled to reproduce reliably.&lt;/p&gt;
&lt;p&gt;A response similar to the following is expected from CloudFront:&lt;/p&gt;
&lt;p&gt;```
HTTP/2 500 
content-type: text/html
content-length: 166541
date: Thu, 09 Apr 2026 12:53:08 GMT
last-modified: Wed, 21 Jan 2026 13:40:08 GMT
etag: &amp;#34;a68349e96c2faf8861c330aeb548441a&amp;#34;
x-amz-server-side-encryption: AES256
accept-ranges: bytes
server: AmazonS3
x-cache: Error from cloudfront
via: 1.1 3591be88662e5675a9dc1cc4e0a9c392.cloudfront.net (CloudFront)
x-amz-cf-pop: ZRH55-P2
x-am…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @astrojs/node&lt;/p&gt;
&lt;p&gt;### Summary
Requesting a static JS/CSS resource from the `_astro` path with an incorrect or malformed `if-match` header returns a `500` error with a one-year cache lifetime instead of `412` in some cases. As a result, all subsequent requests to that file — regardless of the `if-match` header — will be served a 5xx error instead of the file until the cache expires.&lt;/p&gt;
&lt;p&gt;Sending an incorrect or malformed `if-match` header should always return a `412` error without any cache headers, which is not the current behavior.&lt;/p&gt;
&lt;p&gt;### Affected Versions
- `astro@5.14.1`
- `@astrojs/node@9.4.4`&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;Run the following command:&lt;/p&gt;
&lt;p&gt;```
curl -s -o /dev/null -D - &amp;lt;host location&amp;gt;/_astro/_slug_.UTbyeVfw.css -H &amp;#34;if-match: xxx&amp;#34;
```&lt;/p&gt;
&lt;p&gt;If a 5xx error is not returned, inspect the resources via the browser&amp;#39;s web inspector and select another CSS/JS file to request until a 5xx error is returned. The behavior generally defaults to a 5xx response. Note that all static files are immutable, so the cache must be purged or disabled to reproduce reliably.&lt;/p&gt;
&lt;p&gt;A response similar to the following is expected from CloudFront:&lt;/p&gt;
&lt;p&gt;```
HTTP/2 500 
content-type: text/html
content-length: 166541
date: Thu, 09 Apr 2026 12:53:08 GMT
last-modified: Wed, 21 Jan 2026 13:40:08 GMT
etag: &amp;#34;a68349e96c2faf8861c330aeb548441a&amp;#34;
x-amz-server-side-encryption: AES256
accept-ranges: bytes
server: AmazonS3
x-cache: Error from cloudfront
via: 1.1 3591be88662e5675a9dc1cc4e0a9c392.cloudfront.net (CloudFront)
x-amz-cf-pop: ZRH55-P2
x-am…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c57f-mm3j-27q9</guid>
    </item>
  </channel>
</rss>
