<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:36:37.563449+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-215145</id>
    <title>EUVD-2026-215145</title>
    <updated>2026-10-02T15:36:37.662074+00:00</updated>
    <content>EUVD-2026-215145</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-215145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-23216</id>
    <title>fkie_cve-2025-23216</title>
    <updated>2026-10-02T15:36:37.662113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-23216"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-47g2-qmh2-749v</id>
    <title>GHSA-47g2-qmh2-749v — Argo CD does not scrub secret values from patch errors</title>
    <updated>2026-10-02T15:36:37.662162+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/argoproj/argo-cd/v2, Go: github.com/argoproj/argo-cd</p>
<p>### Impact</p>
<p>A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository.</p>
<p>The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data.</p>
<p>### Patches
A patch for this vulnerability is available in the following Argo CD versions:
- v2.13.4
- v2.12.10
- v2.11.13</p>
<p>### Workarounds
There is no workaround other than upgrading.</p>
<p>### References
Fixed with commit https://github.com/argoproj/argo-cd/commit/6f5537bdf15ddbaa0f27a1a678632ff0743e4107 &amp; https://github.com/argoproj/gitops-engine/commit/7e21b91e9d0f64104c8a661f3f390c5e6d73ddca</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-47g2-qmh2-749v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14732-1</id>
    <title>openSUSE-SU-2025:14732-1 — govulncheck-vulndb-0.0.20250204T220613-1.1 on GA media</title>
    <updated>2026-10-02T15:36:37.662229+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250204T220613-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14732-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:1888</id>
    <title>RHSA-2025:1888 — Red Hat Security Advisory: Errata Advisory for Red Hat OpenShift GitOps v1.15.1 security update</title>
    <updated>2026-10-02T15:36:37.662285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies argocd: Argo CD does not scrub secret values from patch errors</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:1888"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0429-1</id>
    <title>SUSE-SU-2025:0429-1 — Security update for govulncheck-vulndb</title>
    <updated>2026-10-02T15:36:37.662319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for govulncheck-vulndb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0429-1"/>
  </entry>
</feed>
