<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:15:55 +0000</lastBuildDate>
    <item>
      <title>BIT-mongoose-2026-42334 — Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection</title>
      <link>https://cve.radiocsirt.org/vuln/bit-mongoose-2026-42334</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mongoose&lt;/p&gt;
&lt;p&gt;Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to neutralize them. However, prior to the fix, $nor was not included in the set of logical operators that are recursively sanitized. Because $nor accepts an array (like $and and $or), and arrays do not trigger hasDollarKeys(), malicious operators such as $ne, $gt, or $regex could be injected inside a $nor clause without being sanitized. This vulnerability is fixed in 6.13.9, 7.8.9, 8.22.1, and 9.1.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mongoose&lt;/p&gt;
&lt;p&gt;Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to neutralize them. However, prior to the fix, $nor was not included in the set of logical operators that are recursively sanitized. Because $nor accepts an array (like $and and $or), and arrays do not trigger hasDollarKeys(), malicious operators such as $ne, $gt, or $regex could be injected inside a $nor clause without being sanitized. This vulnerability is fixed in 6.13.9, 7.8.9, 8.22.1, and 9.1.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-mongoose-2026-42334</guid>
    </item>
    <item>
      <title>EUVD-2026-318582</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318582</link>
      <description>EUVD-2026-318582</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318582</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42334</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42334</link>
      <description>&lt;p&gt;Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to neutralize them. However, prior to the fix, $nor was not included in the set of logical operators that are recursively sanitized. Because $nor accepts an array (like $and and $or), and arrays do not trigger hasDollarKeys(), malicious operators such as $ne, $gt, or $regex could be injected inside a $nor clause without being sanitized. This vulnerability is fixed in 6.13.9, 7.8.9, 8.22.1, and 9.1.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to neutralize them. However, prior to the fix, $nor was not included in the set of logical operators that are recursively sanitized. Because $nor accepts an array (like $and and $or), and arrays do not trigger hasDollarKeys(), malicious operators such as $ne, $gt, or $regex could be injected inside a $nor clause without being sanitized. This vulnerability is fixed in 6.13.9, 7.8.9, 8.22.1, and 9.1.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42334</guid>
    </item>
    <item>
      <title>GHSA-wpg9-53fq-2r8h — Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wpg9-53fq-2r8h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mongoose&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the `$nor` operator.&lt;/p&gt;
&lt;p&gt;When sanitizeFilter is enabled, Mongoose wraps query operators in `$eq` to neutralize them. However, prior to the fix, `$nor` was not included in the set of logical operators that are recursively sanitized. Because `$nor` accepts an array (like `$and` and `$or`), and arrays do not trigger `hasDollarKeys()`, malicious operators such as `$ne`, `$gt`, or `$regex` could be injected inside a `$nor` clause without being sanitized.&lt;/p&gt;
&lt;p&gt;This may lead to:&lt;/p&gt;
&lt;p&gt;- Authentication bypass
- Unauthorized data access
- Data exfiltration&lt;/p&gt;
&lt;p&gt;**Affected users:**&lt;/p&gt;
&lt;p&gt;Applications that:&lt;/p&gt;
&lt;p&gt;- Explicitly enable sanitizeFilter
- Pass unsanitized user-controlled input directly into query methods (e.g., `Model.findOne(req.body)`) and rely on `sanitizeFilter` to strip out query selectors&lt;/p&gt;
&lt;p&gt;Applications that validate input schemas, whitelist fields, or avoid passing raw request bodies into queries are not affected. For example, `Model.findOne({ user: req.body.user, pwd: req.body.pwd })` is not affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patches have been released for all supported Mongoose release lines:&lt;/p&gt;
&lt;p&gt;- `^6.13.9`
- `^7.8.9`
- `^8.22.1`
- `^9.1.6`&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Delete `$nor` keys, use an additional schema validation library, or write middleware to strip out `$nor` from query filters.&lt;/p&gt;
&lt;p&gt;### Resources&lt;/p&gt;
&lt;p&gt;sanitizeFilter documentation: https://mongoosejs.com/docs/api/mongoose.html#Mongoose.prototype.sanitiz…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mongoose&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the `$nor` operator.&lt;/p&gt;
&lt;p&gt;When sanitizeFilter is enabled, Mongoose wraps query operators in `$eq` to neutralize them. However, prior to the fix, `$nor` was not included in the set of logical operators that are recursively sanitized. Because `$nor` accepts an array (like `$and` and `$or`), and arrays do not trigger `hasDollarKeys()`, malicious operators such as `$ne`, `$gt`, or `$regex` could be injected inside a `$nor` clause without being sanitized.&lt;/p&gt;
&lt;p&gt;This may lead to:&lt;/p&gt;
&lt;p&gt;- Authentication bypass
- Unauthorized data access
- Data exfiltration&lt;/p&gt;
&lt;p&gt;**Affected users:**&lt;/p&gt;
&lt;p&gt;Applications that:&lt;/p&gt;
&lt;p&gt;- Explicitly enable sanitizeFilter
- Pass unsanitized user-controlled input directly into query methods (e.g., `Model.findOne(req.body)`) and rely on `sanitizeFilter` to strip out query selectors&lt;/p&gt;
&lt;p&gt;Applications that validate input schemas, whitelist fields, or avoid passing raw request bodies into queries are not affected. For example, `Model.findOne({ user: req.body.user, pwd: req.body.pwd })` is not affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patches have been released for all supported Mongoose release lines:&lt;/p&gt;
&lt;p&gt;- `^6.13.9`
- `^7.8.9`
- `^8.22.1`
- `^9.1.6`&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Delete `$nor` keys, use an additional schema validation library, or write middleware to strip out `$nor` from query filters.&lt;/p&gt;
&lt;p&gt;### Resources&lt;/p&gt;
&lt;p&gt;sanitizeFilter documentation: https://mongoosejs.com/docs/api/mongoose.html#Mongoose.prototype.sanitiz…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wpg9-53fq-2r8h</guid>
    </item>
  </channel>
</rss>
