<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T18:45:53.505602+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-5611</id>
    <title>EUVD-2026-5611</title>
    <updated>2026-10-08T18:45:53.507769+00:00</updated>
    <content>EUVD-2026-5611</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-5611"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35232</id>
    <title>fkie_cve-2024-35232</title>
    <updated>2026-10-08T18:45:53.507801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/huandu/facebook is a Go package that fully supports the Facebook Graph API with file upload, batch request and marketing API. access_token can be exposed in error message on fail in HTTP request. This issue has been patched in version 2.7.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-35232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3f65-m234-9mxr</id>
    <title>GHSA-3f65-m234-9mxr — github.com/huandu/facebook may expose access_token in error message.</title>
    <updated>2026-10-08T18:45:53.507832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/huandu/facebook/v2</p>
<p>### Summary
access_token can be exposed in error message on fail in HTTP request.</p>
<p>### Details
Using this module, when HTTP request fails, error message can contain access_token. This can be happen when:
- module is sending HTTP request with query parameter `?access_token=...`.
- and HTTP request fails (errors like `facebook: cannot reach facebook server`).</p>
<p>In such situation, error message is constucted like following.
https://github.com/huandu/facebook/blob/1591be276561bbdb019c0279f1d33cb18a650e1b/session.go#L558-L567
Original error message contained in it comes from `net/http` module. And it can contain full URL, that can contain query parameter `access_token`:
https://cs.opensource.google/go/go/+/refs/tags/go1.22.3:src/net/http/client.go;l=629-633
https://cs.opensource.google/go/go/+/refs/tags/go1.22.3:src/net/url/url.go;l=30</p>
<p>It should be very common that applications log error message when they encounter errors. As a result, access_token can be stored into log server and some other infrastructures. Of course other careless error handling in client code that causing other security problems can exist.</p>
<p>I'm not very sure that whether we can consider that github.com/huandu/facebook is vulnerable. Anyway, I think current error message, that can expose access_token, is not desirble.</p>
<p>### PoC
Request me this section if you need complete instruction.</p>
<p>### Impact
Client applications with following conditions can be affected.
- logs error message from this module
- or returns er…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3f65-m234-9mxr"/>
  </entry>
</feed>
