<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:40:21.625992+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05665</id>
    <title>bdu:2026-05665</title>
    <updated>2026-10-03T02:40:21.710444+00:00</updated>
    <content>bdu:2026-05665</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05665"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-vault-2026-4525</id>
    <title>BIT-vault-2026-4525 — Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header</title>
    <updated>2026-10-03T02:40:21.710483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: vault</p>
<p>If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-vault-2026-4525"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337229</id>
    <title>EUVD-2026-337229</title>
    <updated>2026-10-03T02:40:21.710535+00:00</updated>
    <content>EUVD-2026-337229</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337229"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4525</id>
    <title>fkie_cve-2026-4525</title>
    <updated>2026-10-03T02:40:21.710566+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-4525"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-72gw-fmmr-c4r4</id>
    <title>GHSA-72gw-fmmr-c4r4 — HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization</title>
    <updated>2026-10-03T02:40:21.710604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/hashicorp/vault</p>
<p>If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-72gw-fmmr-c4r4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1164</id>
    <title>WID-SEC-W-2026-1164 — Hashicorp Vault Community Edition und Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T02:40:21.710640+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Hashicorp Vault ausnutzen, um Daten zu manipulieren, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen, was möglicherweise eine Privilegienerweiterung ermöglicht.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1164"/>
  </entry>
</feed>
