<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:46:07.826219+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-61729</id>
    <title>CVE-2025-61729 — Excessive resource consumption when printing error string for host certificate validation in crypto/x509</title>
    <updated>2026-10-05T18:46:07.901847+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go standard library crypto/x509</p>
<p>Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-61729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2464-8j7c-4cjm</id>
    <title>GHSA-2464-8j7c-4cjm — go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data</title>
    <updated>2026-10-05T18:46:07.901910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/go-viper/mapstructure/v2</p>
<p>### Summary</p>
<p>Use of this library in a security-critical context may result in leaking sensitive information, if used to process sensitive fields.</p>
<p>### Details</p>
<p>OpenBao (and presumably HashiCorp Vault) have surfaced error messages from `mapstructure` as follows:</p>
<p>https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L43-L50</p>
<p>```go
			_, _, err := d.getPrimitive(field, schema)
			if err != nil {
				return fmt.Errorf("error converting input for field %q: %w", field, err)
			}
```</p>
<p>where this calls `mapstructure.WeakDecode(...)`: https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L181-L193</p>
<p>```go</p>
<p>func (d *FieldData) getPrimitive(k string, schema *FieldSchema) (interface{}, bool, error) {
	raw, ok := d.Raw[k]
	if !ok {
		return nil, false, nil
	}</p>
<p>switch t := schema.Type; t {
	case TypeBool:
		var result bool
		if err := mapstructure.WeakDecode(raw, &amp;result); err != nil {
			return nil, false, err
		}
		return result, true, nil
```</p>
<p>Notably, `WeakDecode(...)` eventually calls one of the decode helpers, which surfaces the original value via `strconv` helpers:</p>
<p>https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L720-L727</p>
<p>https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L791-L798</p>
<p>https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2464-8j7c-4cjm"/>
  </entry>
</feed>
