<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:42:54.675067+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06973</id>
    <title>bdu:2025-06973</title>
    <updated>2026-10-02T17:42:54.736440+00:00</updated>
    <content>bdu:2025-06973</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06973"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-openbao-2025-4166</id>
    <title>BIT-openbao-2025-4166 — Vault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin</title>
    <updated>2026-10-02T17:42:54.736479+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: openbao</p>
<p>Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-openbao-2025-4166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-238401</id>
    <title>EUVD-2026-238401</title>
    <updated>2026-10-02T17:42:54.736513+00:00</updated>
    <content>EUVD-2026-238401</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-238401"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4166</id>
    <title>fkie_cve-2025-4166</title>
    <updated>2026-10-02T17:42:54.736526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-4166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gcqf-f89c-68hv</id>
    <title>GHSA-gcqf-f89c-68hv — Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information</title>
    <updated>2026-10-02T17:42:54.736548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/hashicorp/vault</p>
<p>Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gcqf-f89c-68hv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15059-1</id>
    <title>openSUSE-SU-2025:15059-1 — govulncheck-vulndb-0.0.20250506T153719-1.1 on GA media</title>
    <updated>2026-10-02T17:42:54.736568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250506T153719-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15059-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0933</id>
    <title>WID-SEC-W-2025-0933 — Hashicorp Vault: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:42:54.736591+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Hashicorp Vault ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0933"/>
  </entry>
</feed>
