<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:54:51.148646+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08724</id>
    <title>bdu:2026-08724</title>
    <updated>2026-10-03T20:54:51.270838+00:00</updated>
    <content>bdu:2026-08724</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-openbao-2026-39946</id>
    <title>BIT-openbao-2026-39946 — OpenBao allows SQL Injection in PostgreSQL database secrets engine</title>
    <updated>2026-10-03T20:54:51.270887+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: openbao</p>
<p>OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-openbao-2026-39946"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292189</id>
    <title>EUVD-2026-292189</title>
    <updated>2026-10-03T20:54:51.270928+00:00</updated>
    <content>EUVD-2026-292189</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292189"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39946</id>
    <title>fkie_cve-2026-39946</title>
    <updated>2026-10-03T20:54:51.270943+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39946"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6vgr-cp5c-ffx3</id>
    <title>GHSA-6vgr-cp5c-ffx3 — OpenBao's SQL Injection in PostgreSQL database secrets engine</title>
    <updated>2026-10-03T20:54:51.270969+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/openbao/openbao</p>
<p>### Impact</p>
<p>When OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user.</p>
<p>This vulnerability was originally from HashiCorp Vault.</p>
<p>### Patches</p>
<p>This was addressed in v2.5.3.</p>
<p>### Workarounds</p>
<p>Audit table schemas and ensure database users cannot create new schemas and grant privileges on them.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6vgr-cp5c-ffx3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10594-1</id>
    <title>openSUSE-SU-2026:10594-1 — openbao-2.5.3-1.1 on GA media</title>
    <updated>2026-10-03T20:54:51.271000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openbao-2.5.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10594-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1189</id>
    <title>WID-SEC-W-2026-1189 — OpenBao: Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:54:51.271023+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenBao ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, und um einen SQL-Injection Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1189"/>
  </entry>
</feed>
