<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T16:10:49.525105+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01013</id>
    <title>bdu:2024-01013</title>
    <updated>2026-10-10T16:10:49.530155+00:00</updated>
    <content>bdu:2024-01013</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241781</id>
    <title>EUVD-2026-241781</title>
    <updated>2026-10-10T16:10:49.530198+00:00</updated>
    <content>EUVD-2026-241781</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23840</id>
    <title>fkie_cve-2024-23840</title>
    <updated>2026-10-10T16:10:49.530218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-23840"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h3q2-8whx-c29h</id>
    <title>GHSA-h3q2-8whx-c29h — `goreleaser release --debug` shows secrets</title>
    <updated>2026-10-10T16:10:49.530257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/goreleaser/goreleaser</p>
<p>### Summary
Hello 👋</p>
<p>`goreleaser release --debug` log shows secret values used in the in the custom publisher.</p>
<p>How to reproduce the issue:</p>
<p>- Define a custom publisher as the one below. Make sure to provide a custom script to the `cmd` field and to provide a secret to `env`</p>
<p>```
#.goreleaser.yml 
publishers:
  - name: my-publisher
  # IDs of the artifacts we want to sign
    ids:
      - linux_archives
      - linux_package
    cmd: "./build/package/linux_notarize.sh"
    env:
      - VERSION={{ .Version }}
      - SECRET_1={{.Env.SECRET_1}}
      - SECRET_2={{.Env.SECRET_2}}
```</p>
<p>- run `goreleaser release --debug`</p>
<p>You should see your secret value in the gorelease log. The log shows also the `GITHUB_TOKEN`</p>
<p>Example:</p>
<p>```
running                                        cmd= ....
SECRET_1=secret_value
```</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h3q2-8whx-c29h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-23840</id>
    <title>gsd-2024-23840</title>
    <updated>2026-10-10T16:10:49.530315+00:00</updated>
    <content>gsd-2024-23840</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-23840"/>
  </entry>
</feed>
