<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:34:27.783111+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:34357</id>
    <title>ALSA-2026:34357 — Important: opentelemetry-collector security update</title>
    <updated>2026-10-02T11:34:28.945560+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: opentelemetry-collector</p>
<p>Collector with the supported components for a AlmaLinux build of OpenTelemetry</p>
<p>Security Fix(es):</p>
<p>* github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)
  * github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)
  * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  * golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
  * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
  * crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:34357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-prometheus-2026-42151</id>
    <title>BIT-prometheus-2026-42151 — Prometheus Azure AD remote write OAuth client secret exposed via config API</title>
    <updated>2026-10-02T11:34:28.945680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: prometheus</p>
<p>Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-prometheus-2026-42151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ap95632</id>
    <title>Withdrawn: CLEANSTART-2026-AP95632 — Security fixes for CVE-2026-25679, CVE-2026-27139, CVE-2026-27142, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-…</title>
    <updated>2026-10-02T11:34:28.945726+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: keda-fips</p>
<p>Multiple security vulnerabilities affect the keda-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ap95632"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366101</id>
    <title>EUVD-2026-366101</title>
    <updated>2026-10-02T11:34:28.945774+00:00</updated>
    <content>EUVD-2026-366101</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366101"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42151</id>
    <title>fkie_cve-2026-42151</title>
    <updated>2026-10-02T11:34:28.945794+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wg65-39gg-5wfj</id>
    <title>GHSA-wg65-39gg-5wfj — Prometheus Azure AD remote write OAuth client secret exposed via config API</title>
    <updated>2026-10-02T11:34:28.945844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/prometheus/prometheus</p>
<p>### Impact</p>
<p>Users who use Azure AD remote write with OAuth authentication are impacted.</p>
<p>The `client_secret` field in the Azure AD remote write OAuth configuration (`storage/remote/azuread`) was typed as `string` instead of `Secret`. Prometheus redacts fields of type `Secret` when serving the configuration via the `/-/config` HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint.</p>
<p>### Patches</p>
<p>The problem has been patched by changing `ClientSecret` in `OAuthConfig` to `Secret`. Users should upgrade to 3.11.3 or 3.5.3 LTS.</p>
<p>### Workarounds</p>
<p>Users  who can not upgrade can switch to Managed Identity or Workload Identity authentication for Azure AD remote write, which do not involve a client secret.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wg65-39gg-5wfj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42151</id>
    <title>msrc_CVE-2026-42151 — Prometheus Azure AD remote write OAuth client secret exposed via config API</title>
    <updated>2026-10-02T11:34:28.945875+00:00</updated>
    <content>msrc_CVE-2026-42151</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-42151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10676-1</id>
    <title>openSUSE-SU-2026:10676-1 — golang-github-prometheus-prometheus-3.11.3-1.1 on GA media</title>
    <updated>2026-10-02T11:34:28.945893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang-github-prometheus-prometheus-3.11.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10676-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:25039</id>
    <title>RHSA-2026:25039 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T11:34:28.945909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression python-idna: idna: Denial of Service via specially crafted long inputs joserfc: joserfc: Resource exhaustion via oversized JSON Web Signature (JWS) payloads</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:25039"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:34357</id>
    <title>RLSA-2026:34357 — Important: opentelemetry-collector security update</title>
    <updated>2026-10-02T11:34:28.945934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: opentelemetry-collector</p>
<p>Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry</p>
<p>Security Fix(es):</p>
<p>* github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)</p>
<p>* github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)</p>
<p>* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)</p>
<p>* golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)</p>
<p>* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)</p>
<p>* crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:34357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:2774-1</id>
    <title>SUSE-SU-2026:2774-1 — Security update 5.1.4 for Multi-Linux Manager Server</title>
    <updated>2026-10-02T11:34:28.945963+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 5.1.4 for Multi-Linux Manager Server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:2774-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42151</id>
    <title>UBUNTU-CVE-2026-42151</title>
    <updated>2026-10-02T11:34:28.945986+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: prometheus, Ubuntu:18.04:LTS: prometheus, Ubuntu:20.04:LTS: prometheus, Ubuntu:Pro:22.04:LTS: prometheus, Ubuntu:Pro:24.04:LTS: prometheus, Ubuntu:25.10: prometheus, Ubuntu:Pro:26.04:LTS: prometheus</p>
<p>Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1292</id>
    <title>WID-SEC-W-2026-1292 — Prometheus: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:34:28.946015+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Prometheus ausnutzen, um einen Denial of Service Angriff durchzuführen, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1292"/>
  </entry>
</feed>
