<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 13:21:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-338550</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338550</link>
      <description>EUVD-2026-338550</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338550</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49215</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49215</link>
      <description>&lt;p&gt;Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber::isLiveComponentRequest() gates #[LiveAction] invocations on Accept: application/vnd.live-component+html, but the Accept header is CORS-safelisted and cross-origin fetch() can set it without preflight, allowing forged cross-origin #[LiveAction] requests against a victim session when applications use SameSite=None, credentials: &amp;#39;include&amp;#39;, a permissive cookie policy, or a same-origin pivot. This issue is fixed in versions 2.36.0 and 3.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber::isLiveComponentRequest() gates #[LiveAction] invocations on Accept: application/vnd.live-component+html, but the Accept header is CORS-safelisted and cross-origin fetch() can set it without preflight, allowing forged cross-origin #[LiveAction] requests against a victim session when applications use SameSite=None, credentials: &amp;#39;include&amp;#39;, a permissive cookie policy, or a same-origin pivot. This issue is fixed in versions 2.36.0 and 3.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49215</guid>
    </item>
    <item>
      <title>GHSA-4m4j-hmqq-3gxm — symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4m4j-hmqq-3gxm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: symfony/ux-live-component&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;When using `symfony/ux-live-component`, methods annotated with `#[LiveAction]` are invokable from the browser and mutate server-side state via AJAX. `Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber::isLiveComponentRequest()` gated these invocations on the presence of `Accept: application/vnd.live-component+html`, with a code comment stating that this acted as a CSRF protection.&lt;/p&gt;
&lt;p&gt;The `Accept` header is a [CORS-safelisted request header](https://fetch.spec.whatwg.org/#cors-safelisted-request-header), so a cross-origin `fetch()` can set it without triggering a preflight. The header therefore provided no CSRF protection. Any `#[LiveAction]` could be forged cross-origin against a victim&amp;#39;s session.&lt;/p&gt;
&lt;p&gt;In practice the attack is mitigated by `SameSite=Lax` session cookies (Symfony&amp;#39;s default), but applications using `SameSite=None`, `credentials: &amp;#39;include&amp;#39;` with a permissive cookie policy, or that have been pivoted from another same-origin vector remained exposed.&lt;/p&gt;
&lt;p&gt;### Resolution&lt;/p&gt;
&lt;p&gt;`isLiveComponentRequest()` now additionally requires the request header `X-Requested-With: XMLHttpRequest`. This header is **not** CORS-safelisted, so the browser issues a preflight `OPTIONS` request for any cross-origin attempt; Symfony does not advertise CORS for LiveComponent endpoints, the preflight fails, and the real request is blocked before it reaches the application. The bundled Stimulus client already sends `X-Requested-With` on every LiveComponent request (`RequestBu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: symfony/ux-live-component&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;When using `symfony/ux-live-component`, methods annotated with `#[LiveAction]` are invokable from the browser and mutate server-side state via AJAX. `Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber::isLiveComponentRequest()` gated these invocations on the presence of `Accept: application/vnd.live-component+html`, with a code comment stating that this acted as a CSRF protection.&lt;/p&gt;
&lt;p&gt;The `Accept` header is a [CORS-safelisted request header](https://fetch.spec.whatwg.org/#cors-safelisted-request-header), so a cross-origin `fetch()` can set it without triggering a preflight. The header therefore provided no CSRF protection. Any `#[LiveAction]` could be forged cross-origin against a victim&amp;#39;s session.&lt;/p&gt;
&lt;p&gt;In practice the attack is mitigated by `SameSite=Lax` session cookies (Symfony&amp;#39;s default), but applications using `SameSite=None`, `credentials: &amp;#39;include&amp;#39;` with a permissive cookie policy, or that have been pivoted from another same-origin vector remained exposed.&lt;/p&gt;
&lt;p&gt;### Resolution&lt;/p&gt;
&lt;p&gt;`isLiveComponentRequest()` now additionally requires the request header `X-Requested-With: XMLHttpRequest`. This header is **not** CORS-safelisted, so the browser issues a preflight `OPTIONS` request for any cross-origin attempt; Symfony does not advertise CORS for LiveComponent endpoints, the preflight fails, and the real request is blocked before it reaches the application. The bundled Stimulus client already sends `X-Requested-With` on every LiveComponent request (`RequestBu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4m4j-hmqq-3gxm</guid>
    </item>
  </channel>
</rss>
