<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:09:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326965</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326965</link>
      <description>EUVD-2026-326965</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326965</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53721</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53721</link>
      <description>&lt;p&gt;Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53721</guid>
    </item>
    <item>
      <title>GHSA-mm7m-92g8-7m47 — Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mm7m-92g8-7m47</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nuxt&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Nuxt looks up `routeRules` for the current navigation by calling
`getRouteRules({ path: to.path })` from the page-router plugin and the
no-pages router plugin. The compiled `routeRules` matcher (built on
`rou3`) performs case-sensitive matching, while vue-router is configured
with its default `sensitive: false` and matches paths case-insensitively.&lt;/p&gt;
&lt;p&gt;The two routers therefore disagree on which rules apply to a given
request path: vue-router still matches the page record for
`/Admin/dashboard`, but the `routeRules` lookup for the same path
returns no match. Any `appMiddleware` declared via `routeRules` is never
added to the middleware set and never runs, on both SSR and client
navigations. The same path skips other path-keyed route rules in the
same way (`ssr`, `redirect`, `appLayout`, and the prerender / payload
hints used client-side).&lt;/p&gt;
&lt;p&gt;For applications using `routeRules` with `appMiddleware` as an
authorization gate (a documented pattern), an attacker can flip the case
of any static segment in a protected URL (for example `/Admin/dashboard`
instead of `/admin/dashboard`) to render the protected page with the
middleware skipped. The server returns the fully server-rendered page
including any `useFetch` / `useAsyncData` results captured during SSR.&lt;/p&gt;
&lt;p&gt;This is an instance of CWE-178 (Improper Handling of Case Sensitivity)
leading to CWE-863 (Incorrect Authorization) for apps that treat
`appMiddleware` as an authorization boundary.&lt;/p&gt;
&lt;p&gt;## Mitigating factors&lt;/p&gt;
&lt;p&gt;- Only affect…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nuxt&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Nuxt looks up `routeRules` for the current navigation by calling
`getRouteRules({ path: to.path })` from the page-router plugin and the
no-pages router plugin. The compiled `routeRules` matcher (built on
`rou3`) performs case-sensitive matching, while vue-router is configured
with its default `sensitive: false` and matches paths case-insensitively.&lt;/p&gt;
&lt;p&gt;The two routers therefore disagree on which rules apply to a given
request path: vue-router still matches the page record for
`/Admin/dashboard`, but the `routeRules` lookup for the same path
returns no match. Any `appMiddleware` declared via `routeRules` is never
added to the middleware set and never runs, on both SSR and client
navigations. The same path skips other path-keyed route rules in the
same way (`ssr`, `redirect`, `appLayout`, and the prerender / payload
hints used client-side).&lt;/p&gt;
&lt;p&gt;For applications using `routeRules` with `appMiddleware` as an
authorization gate (a documented pattern), an attacker can flip the case
of any static segment in a protected URL (for example `/Admin/dashboard`
instead of `/admin/dashboard`) to render the protected page with the
middleware skipped. The server returns the fully server-rendered page
including any `useFetch` / `useAsyncData` results captured during SSR.&lt;/p&gt;
&lt;p&gt;This is an instance of CWE-178 (Improper Handling of Case Sensitivity)
leading to CWE-863 (Incorrect Authorization) for apps that treat
`appMiddleware` as an authorization boundary.&lt;/p&gt;
&lt;p&gt;## Mitigating factors&lt;/p&gt;
&lt;p&gt;- Only affect…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mm7m-92g8-7m47</guid>
    </item>
  </channel>
</rss>
