<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 09:49:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-370603</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-370603</link>
      <description>EUVD-2026-370603</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-370603</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63460</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63460</link>
      <description>&lt;p&gt;Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service/helpers/list-query-builder/parse-filter-params.ts passes the raw pattern to the REGEXP implementation registered by packages/core/src/service/helpers/list-query-builder/list-query-builder.ts, and better-sqlite3 and sqljs evaluate it synchronously in the Node.js event loop. ShopProductsResolver.products is publicly reachable, so one nested-quantifier pattern can block request processing and make the storefront and admin API unavailable, while repeated requests can sustain denial of service. PostgreSQL and MySQL or MariaDB deployments do not execute this regular expression in the Node.js event loop. This issue is fixed in version 3.6.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service/helpers/list-query-builder/parse-filter-params.ts passes the raw pattern to the REGEXP implementation registered by packages/core/src/service/helpers/list-query-builder/list-query-builder.ts, and better-sqlite3 and sqljs evaluate it synchronously in the Node.js event loop. ShopProductsResolver.products is publicly reachable, so one nested-quantifier pattern can block request processing and make the storefront and admin API unavailable, while repeated requests can sustain denial of service. PostgreSQL and MySQL or MariaDB deployments do not execute this regular expression in the Node.js event loop. This issue is fixed in version 3.6.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63460</guid>
    </item>
    <item>
      <title>GHSA-jgm3-qmp2-c4p7 — Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jgm3-qmp2-c4p7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @vendure/core&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;&amp;gt; [!IMPORTANT] 
&amp;gt; Only instances running on the SQLite driver (better-sqlite3) are affected; SQLite is usually used in development/testing backend, so production deployments on PostgreSQL or MySQL/MariaDB are unaffected.&lt;/p&gt;
&lt;p&gt;The `StringOperators.regex` filter exposed on the public Shop GraphQL API is evaluated inside the Node.js event loop via a synchronous SQLite user-defined function (UDF). Supplying a catastrophically backtracking pattern blocks the entire event loop, causing a complete denial of service with no authentication required.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Vendure registers a JavaScript UDF so that SQLite can handle the `REGEXP` operator:&lt;/p&gt;
&lt;p&gt;**`packages/core/src/service/helpers/list-query-builder/list-query-builder.ts` lines 917–931**
```ts
private registerSQLiteRegexpFunction() {
    const regexpFn = (pattern: string, value: string) =&amp;gt; {
        const result = new RegExp(`${pattern}`, &amp;#39;i&amp;#39;).test(value);  // user-controlled pattern
        return result ? 1 : 0;
    };
    if (dbType === &amp;#39;better-sqlite3&amp;#39;) {
        driver.databaseConnection.function(&amp;#39;regexp&amp;#39;, regexpFn);
    }
    if (dbType === &amp;#39;sqljs&amp;#39;) {
        driver.databaseConnection.create_function(&amp;#39;regexp&amp;#39;, regexpFn);
    }
}
```&lt;/p&gt;
&lt;p&gt;The `pattern` argument is the raw value of `StringOperators.regex` submitted by the caller. No length limit, timeout, or safe-regex validation is applied before constructing `new RegExp(pattern)`.&lt;/p&gt;
&lt;p&gt;**`packages/core/src/service/helpers/list-query-builder/parse-filter-params.ts` lines…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @vendure/core&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;&amp;gt; [!IMPORTANT] 
&amp;gt; Only instances running on the SQLite driver (better-sqlite3) are affected; SQLite is usually used in development/testing backend, so production deployments on PostgreSQL or MySQL/MariaDB are unaffected.&lt;/p&gt;
&lt;p&gt;The `StringOperators.regex` filter exposed on the public Shop GraphQL API is evaluated inside the Node.js event loop via a synchronous SQLite user-defined function (UDF). Supplying a catastrophically backtracking pattern blocks the entire event loop, causing a complete denial of service with no authentication required.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Vendure registers a JavaScript UDF so that SQLite can handle the `REGEXP` operator:&lt;/p&gt;
&lt;p&gt;**`packages/core/src/service/helpers/list-query-builder/list-query-builder.ts` lines 917–931**
```ts
private registerSQLiteRegexpFunction() {
    const regexpFn = (pattern: string, value: string) =&amp;gt; {
        const result = new RegExp(`${pattern}`, &amp;#39;i&amp;#39;).test(value);  // user-controlled pattern
        return result ? 1 : 0;
    };
    if (dbType === &amp;#39;better-sqlite3&amp;#39;) {
        driver.databaseConnection.function(&amp;#39;regexp&amp;#39;, regexpFn);
    }
    if (dbType === &amp;#39;sqljs&amp;#39;) {
        driver.databaseConnection.create_function(&amp;#39;regexp&amp;#39;, regexpFn);
    }
}
```&lt;/p&gt;
&lt;p&gt;The `pattern` argument is the raw value of `StringOperators.regex` submitted by the caller. No length limit, timeout, or safe-regex validation is applied before constructing `new RegExp(pattern)`.&lt;/p&gt;
&lt;p&gt;**`packages/core/src/service/helpers/list-query-builder/parse-filter-params.ts` lines…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jgm3-qmp2-c4p7</guid>
    </item>
  </channel>
</rss>
