<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:14:58.572256+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331650</id>
    <title>EUVD-2026-331650</title>
    <updated>2026-10-04T06:14:58.575167+00:00</updated>
    <content>EUVD-2026-331650</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331650"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54673</id>
    <title>fkie_cve-2026-54673</title>
    <updated>2026-10-04T06:14:58.575199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization", exposing credentials. Other credential-bearing headers — most notably PRIVATE-TOKEN (used by GitLab's personal access token flow) and mixed-case Authorization (used by GitLab's Bearer/OAuth flow) — were not stripped and could be forwarded to an attacker-controlled cross-origin redirect destination. This issue has been fixed in version 9.7.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p2f4-r6v6-j797</id>
    <title>GHSA-p2f4-r6v6-j797 — electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-ut…</title>
    <updated>2026-10-04T06:14:58.575250+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: builder-util-runtime</p>
<p>## Summary</p>
<p>In `electron-builder`'s `builder-util-runtime` package, the HTTP redirect handler (`HttpExecutor.prepareRedirectUrlOptions`) only stripped a credential header whose key string matched exactly lowercase `"authorization"`. Other credential-bearing headers — most notably `PRIVATE-TOKEN` (used by GitLab's personal access token flow) and mixed-case `Authorization` (used by GitLab's Bearer/OAuth flow) — were not stripped and could be forwarded to an attacker-controlled cross-origin redirect destination.</p>
<p>---</p>
<p>## Details</p>
<p>### Root cause</p>
<p>`HttpExecutor.prepareRedirectUrlOptions` (introduced in `builder-util-runtime` via [PR #9211](https://github.com/electron-userland/electron-builder/pull/9211), first released in `v26.0.20`) performed its cross-origin credential strip with a single case-sensitive property check:</p>
<p>```typescript
// vulnerable code (electron-builder v26.0.20 – v26.14.x) [via builder-util-runtime &lt;9.7.0]
if (headers?.authorization) {
  if (HttpExecutor.isCrossOriginRedirect(originalUrl, parsedRedirectUrl)) {
    delete headers.authorization   // only removes the exact key "authorization"
  }
}
```</p>
<p>JavaScript object property access is case-sensitive. The guard `headers?.authorization` evaluates to `undefined` (falsy) when the key is `"Authorization"`, `"AUTHORIZATION"`, or any other casing, so the branch is never entered and **no header is deleted** for those cases.</p>
<p>### Affected updater flows</p>
<p>The clearest reproduced path is the private GitLab updater flow.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p2f4-r6v6-j797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11200-1</id>
    <title>openSUSE-SU-2026:11200-1 — heroic-games-launcher-2.22.0-4.1 on GA media</title>
    <updated>2026-10-04T06:14:58.575319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>heroic-games-launcher-2.22.0-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11200-1"/>
  </entry>
</feed>
