<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:52:50.133778+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-55190</id>
    <title>CVE-2025-55190 — Argo CD: Project API Token Exposes Repository Credentials</title>
    <updated>2026-10-03T08:52:50.364157+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> argoproj argo-cd</p>
<p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets. This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`. This issue is fixed in versions 2.13.9, 2.14.16, 3.0.14 and 3.1.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-55190"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2x5j-vhc8-9cwm</id>
    <title>GHSA-2x5j-vhc8-9cwm — CIRCL-Fourq: Missing and wrong validation can lead to incorrect results</title>
    <updated>2026-10-03T08:52:50.364228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/cloudflare/circl</p>
<p>### Impact
The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security.</p>
<p>Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve.</p>
<p>### Patches
Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues.</p>
<p>We acknowledge Alon Livne (Botanica Software Labs) for the reported findings.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2x5j-vhc8-9cwm"/>
  </entry>
</feed>
