<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 17:18:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-375473</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-375473</link>
      <description>EUVD-2026-375473</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-375473</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48599</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48599</link>
      <description>&lt;p&gt;Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the query string or request body.&lt;/p&gt;
&lt;p&gt;In &amp;#39;Elixir.GRPC.Server.Transcode&amp;#39;:map_request/5 (lib/grpc/server/transcode.ex), all three clauses use Map.merge/2 with path bindings as the first argument, giving them the lowest merge precedence. A request such as GET /users/me/profile?user_id=victim (or a POST with {&amp;#34;user_id&amp;#34;: &amp;#34;victim&amp;#34;} when body: &amp;#34;*&amp;#34;) yields a decoded protobuf struct where the path-bound field carries the attacker-supplied value rather than the router-extracted value. Any handler that uses the path-bound field for authorization, multi-tenancy scoping, or ownership checks is silently bypassed.&lt;/p&gt;
&lt;p&gt;This issue affects grpc: from 0.8.0 before 1.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the query string or request body.&lt;/p&gt;
&lt;p&gt;In &amp;#39;Elixir.GRPC.Server.Transcode&amp;#39;:map_request/5 (lib/grpc/server/transcode.ex), all three clauses use Map.merge/2 with path bindings as the first argument, giving them the lowest merge precedence. A request such as GET /users/me/profile?user_id=victim (or a POST with {&amp;#34;user_id&amp;#34;: &amp;#34;victim&amp;#34;} when body: &amp;#34;*&amp;#34;) yields a decoded protobuf struct where the path-bound field carries the attacker-supplied value rather than the router-extracted value. Any handler that uses the path-bound field for authorization, multi-tenancy scoping, or ownership checks is silently bypassed.&lt;/p&gt;
&lt;p&gt;This issue affects grpc: from 0.8.0 before 1.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48599</guid>
    </item>
    <item>
      <title>GHSA-mwr4-5g34-j5cq — gRPC Erlang package's path bindings are overridable by query string and request body</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mwr4-5g34-j5cq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: grpc&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;In the HTTP-to-gRPC transcoding layer of the `grpc` Hex package, query-string and request-body parameters can silently overwrite path-bound fields when building the decoded protobuf request struct. An authenticated attacker who can reach a transcoded endpoint can substitute any path-bound identifier (e.g. `user_id` from `/users/{user_id}/profile`) with an arbitrary value, bypassing authorization, multi-tenancy, and ownership checks that rely on the path-derived field.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;All three clauses of `GRPC.Server.Transcode.map_request/5` (`grpc_server/lib/grpc/server/transcode.ex`) use `Map.merge/2` with path bindings as the first argument, giving them the lowest merge precedence. Path bindings are extracted by the router from the matched URL template and should be the authoritative resource identifiers, but query-string and body parameters overwrite them. The decoded protobuf struct handed to the handler carries the attacker&amp;#39;s value instead of the router&amp;#39;s.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Deploy a transcoded gRPC service with a route like `GET /users/{user_id}/profile` where the handler authorizes access based on `request.user_id`.
2. Send: `GET /users/me/profile?user_id=victim`
3. The decoded request struct has `user_id = &amp;#34;victim&amp;#34;` — the authorization check passes for the victim&amp;#39;s resource, not the caller&amp;#39;s.
4. Alternatively, for a `POST` with `body: &amp;#34;*&amp;#34;`: send `{&amp;#34;user_id&amp;#34;: &amp;#34;victim&amp;#34;}` in the JSON body.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Affects applications using `grpc` ≥ 0.8.0 with HTTP transcodin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: grpc&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;In the HTTP-to-gRPC transcoding layer of the `grpc` Hex package, query-string and request-body parameters can silently overwrite path-bound fields when building the decoded protobuf request struct. An authenticated attacker who can reach a transcoded endpoint can substitute any path-bound identifier (e.g. `user_id` from `/users/{user_id}/profile`) with an arbitrary value, bypassing authorization, multi-tenancy, and ownership checks that rely on the path-derived field.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;All three clauses of `GRPC.Server.Transcode.map_request/5` (`grpc_server/lib/grpc/server/transcode.ex`) use `Map.merge/2` with path bindings as the first argument, giving them the lowest merge precedence. Path bindings are extracted by the router from the matched URL template and should be the authoritative resource identifiers, but query-string and body parameters overwrite them. The decoded protobuf struct handed to the handler carries the attacker&amp;#39;s value instead of the router&amp;#39;s.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Deploy a transcoded gRPC service with a route like `GET /users/{user_id}/profile` where the handler authorizes access based on `request.user_id`.
2. Send: `GET /users/me/profile?user_id=victim`
3. The decoded request struct has `user_id = &amp;#34;victim&amp;#34;` — the authorization check passes for the victim&amp;#39;s resource, not the caller&amp;#39;s.
4. Alternatively, for a `POST` with `body: &amp;#34;*&amp;#34;`: send `{&amp;#34;user_id&amp;#34;: &amp;#34;victim&amp;#34;}` in the JSON body.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Affects applications using `grpc` ≥ 0.8.0 with HTTP transcodin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mwr4-5g34-j5cq</guid>
    </item>
  </channel>
</rss>
