<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 22:05:41 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-363537</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363537</link>
      <description>EUVD-2026-363537</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363537</guid>
    </item>
    <item>
      <title>fkie_cve-2026-84367</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84367</link>
      <description>&lt;p&gt;joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi&amp;#39;s lib/types/keys.js internals.rename() implementation used by object().rename() permits a schema that renames keys with a regular-expression source and a Joi.expression() or Joi.x() target that interpolates the pattern&amp;#39;s own match data, combined with { multiple: true }, to derive a target from an attacker-controlled input key. An attacker can send x-__proto__ with an object value, causing the target to render as __proto__ and set the prototype of the object returned by validate() instead of creating an own key. The global Object.prototype is not modified, so the effect is confined to the object returned by that validation call. Static-string targets and schemas using the default { multiple: false } are not affected. This issue is fixed in versions 17.13.5 and 18.2.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi&amp;#39;s lib/types/keys.js internals.rename() implementation used by object().rename() permits a schema that renames keys with a regular-expression source and a Joi.expression() or Joi.x() target that interpolates the pattern&amp;#39;s own match data, combined with { multiple: true }, to derive a target from an attacker-controlled input key. An attacker can send x-__proto__ with an object value, causing the target to render as __proto__ and set the prototype of the object returned by validate() instead of creating an own key. The global Object.prototype is not modified, so the effect is confined to the object returned by that validation call. Static-string targets and schemas using the default { multiple: false } are not affected. This issue is fixed in versions 17.13.5 and 18.2.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-84367</guid>
    </item>
    <item>
      <title>GHSA-gg4h-3hg2-grpc — joi: object().rename() with a template target can set the validated object's prototype</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gg4h-3hg2-grpc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: joi&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Applications are affected only if a schema renames keys with a regular-expression source and a `Joi.expression()` / `Joi.x()` target that interpolates the pattern&amp;#39;s own match data, combined with `{ multiple: true }`, for example `.rename(/^x-(.+)$/, Joi.x(&amp;#39;{#1}&amp;#39;), { multiple: true })`. Because the target is rendered from the matched input key, an attacker who controls input keys can send `x-__proto__` with an object value and make the rename target render as `__proto__`, which sets the prototype of the object joi returns instead of creating a key on it. The global `Object.prototype` is not modified, so the effect is confined to the object returned by that one `validate()` call.&lt;/p&gt;
&lt;p&gt;Schemas using a static string rename target are not affected, and neither are schemas left on the default `{ multiple: false }`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Versions 17.13.5 and 18.2.4 have been released to address the issue.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;1. Replace the template rename target with a static string target.
2. Keep the template but make the capture unable to produce `__proto__`, using a negative lookahead: `.rename(/^x-(?!__proto__$)(.+)$/, Joi.x(&amp;#39;{#1}&amp;#39;), { multiple: true })`
3. Drop { multiple: true } from the rename, which stops the rename before the assignment.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: joi&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Applications are affected only if a schema renames keys with a regular-expression source and a `Joi.expression()` / `Joi.x()` target that interpolates the pattern&amp;#39;s own match data, combined with `{ multiple: true }`, for example `.rename(/^x-(.+)$/, Joi.x(&amp;#39;{#1}&amp;#39;), { multiple: true })`. Because the target is rendered from the matched input key, an attacker who controls input keys can send `x-__proto__` with an object value and make the rename target render as `__proto__`, which sets the prototype of the object joi returns instead of creating a key on it. The global `Object.prototype` is not modified, so the effect is confined to the object returned by that one `validate()` call.&lt;/p&gt;
&lt;p&gt;Schemas using a static string rename target are not affected, and neither are schemas left on the default `{ multiple: false }`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Versions 17.13.5 and 18.2.4 have been released to address the issue.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;1. Replace the template rename target with a static string target.
2. Keep the template but make the capture unable to produce `__proto__`, using a negative lookahead: `.rename(/^x-(?!__proto__$)(.+)$/, Joi.x(&amp;#39;{#1}&amp;#39;), { multiple: true })`
3. Drop { multiple: true } from the rename, which stops the rename before the assignment.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gg4h-3hg2-grpc</guid>
    </item>
  </channel>
</rss>
