<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:35:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335645</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335645</link>
      <description>EUVD-2026-335645</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335645</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56669</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56669</link>
      <description>&lt;p&gt;Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to 1.4.29, Elysia uses getAll in form data normalization for multipart/form-data endpoints, causing the amount of work to grow quadratically with the number of unique key-value pairs and allowing CPU exhaustion. This issue is fixed in version 1.4.29.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to 1.4.29, Elysia uses getAll in form data normalization for multipart/form-data endpoints, causing the amount of work to grow quadratically with the number of unique key-value pairs and allowing CPU exhaustion. This issue is fixed in version 1.4.29.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56669</guid>
    </item>
    <item>
      <title>GHSA-9643-4qgh-g8mx — elysia has Inefficient Algorithmic Complexity and Interpretation Conflict</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9643-4qgh-g8mx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: elysia&lt;/p&gt;
&lt;p&gt;Elysia v1.4.28 is vulnerable to denial-of-service attacks due to CPU exhaustion in the form data normalization code.&lt;/p&gt;
&lt;p&gt;Elysia uses `getAll` to retrieve value from FormData. It is called directly relative to the total number of key-value pairs in the form data. The total amount of work the for loop has to do grows quadratically, so doubling the number of unique key-value pairs quadruples the amount of work. In the above PoC, each .getAll call scans through all of the `n` key-value pairs in the form data. Because there are `n` unique keys in the form data, there are .getAll calls, so in total the form data normalizer has to scan `n` x `n` key-value pairs.&lt;/p&gt;
&lt;p&gt;### Impact
Endpoints using `multipart/form-data`&lt;/p&gt;
&lt;p&gt;### Patches
1.4.29&lt;/p&gt;
&lt;p&gt;### Workarounds
no 100% confirm workaround beside updating the patch&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: elysia&lt;/p&gt;
&lt;p&gt;Elysia v1.4.28 is vulnerable to denial-of-service attacks due to CPU exhaustion in the form data normalization code.&lt;/p&gt;
&lt;p&gt;Elysia uses `getAll` to retrieve value from FormData. It is called directly relative to the total number of key-value pairs in the form data. The total amount of work the for loop has to do grows quadratically, so doubling the number of unique key-value pairs quadruples the amount of work. In the above PoC, each .getAll call scans through all of the `n` key-value pairs in the form data. Because there are `n` unique keys in the form data, there are .getAll calls, so in total the form data normalizer has to scan `n` x `n` key-value pairs.&lt;/p&gt;
&lt;p&gt;### Impact
Endpoints using `multipart/form-data`&lt;/p&gt;
&lt;p&gt;### Patches
1.4.29&lt;/p&gt;
&lt;p&gt;### Workarounds
no 100% confirm workaround beside updating the patch&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9643-4qgh-g8mx</guid>
    </item>
  </channel>
</rss>
