<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T01:22:46.421460+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06177</id>
    <title>bdu:2025-06177</title>
    <updated>2026-10-05T01:22:46.532455+00:00</updated>
    <content>bdu:2025-06177</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-vault-2023-24999</id>
    <title>BIT-vault-2023-24999 — Vault Fails to Verify if the AppRole SecretID Belongs to Role During a Destroy Operation</title>
    <updated>2026-10-05T01:22:46.532491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: vault</p>
<p>HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-vault-2023-24999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-220324</id>
    <title>EUVD-2026-220324</title>
    <updated>2026-10-05T01:22:46.532537+00:00</updated>
    <content>EUVD-2026-220324</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-220324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-24999</id>
    <title>fkie_cve-2023-24999</title>
    <updated>2026-10-05T01:22:46.532553+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-24999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wmg5-g953-qqfw</id>
    <title>GHSA-wmg5-g953-qqfw — Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation</title>
    <updated>2026-10-05T01:22:46.532576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/hashicorp/vault</p>
<p>When using the Vault and Vault Enterprise (Vault) approle auth method, any authenticated user with access to the `/auth/approle/role/:role_name/secret-id-accessor/destroy` endpoint can destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability, CVE-2023-24999, has been fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wmg5-g953-qqfw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-24999</id>
    <title>gsd-2023-24999</title>
    <updated>2026-10-05T01:22:46.532600+00:00</updated>
    <content>gsd-2023-24999</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-24999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:3742</id>
    <title>RHSA-2023:3742 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.13.0 security and bug fix update</title>
    <updated>2026-10-05T01:22:46.532612+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vault: Hashicorp Vault AWS IAM Integration Authentication Bypass vault: GCP Auth Method Allows Authentication Bypass validator: Inefficient Regular Expression Complexity in Validator.js nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes go-yaml: Denial of Service in go-yaml goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be vault: incorrect policy enforcement nodejs: Improper handling of URI Subject Alternative Names nodejs: Certificate Verification Bypass via String Injection nodejs: Incorrect handling of certificate subject and issuer fields golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters nodejs-minimatch: ReDoS via the braceExpand function nodejs: Prototype pollution via console.table properties jsonwebtoken: Insecure default algorithm in jwt.verify() could lead to signature validation bypass jsonwebtoken: Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC golang: net/http: handle server errors after sending GOAWAY golang: encoding/gob: stack exhaustion in Decoder.Decode golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service golang: net/url: JoinPath does not strip relative path components in all circumstan…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:3742"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0627</id>
    <title>WID-SEC-W-2023-0627 — Hashicorp Vault: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-05T01:22:46.532681+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Hashicorp Vault ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0627"/>
  </entry>
</feed>
