<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T14:05:27.418130+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276048</id>
    <title>EUVD-2026-276048</title>
    <updated>2026-10-06T14:05:27.466191+00:00</updated>
    <content>EUVD-2026-276048</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32598</id>
    <title>fkie_cve-2026-32598</title>
    <updated>2026-10-06T14:05:27.466233+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user. This vulnerability is fixed in 10.0.24.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32598"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4524-cj9j-g4fj</id>
    <title>GHSA-4524-cj9j-g4fj — OneUptime: Password Reset Token Logged at INFO Level</title>
    <updated>2026-10-06T14:05:27.466270+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: oneuptime</p>
<p>### Summary</p>
<p>The password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user.</p>
<p>### Details</p>
<p>**Vulnerable code — `App/FeatureSet/Identity/API/Authentication.ts` lines 370-371:**
```typescript
logger.info("User forgot password: " + user.email?.toString());
logger.info("Reset Password URL: " + tokenVerifyUrl);
```</p>
<p>The `tokenVerifyUrl` is a complete URL like `https://app.oneuptime.com/accounts/reset-password/&lt;plaintext-token&gt;`. This is logged at INFO level, which is enabled by default in production and persisted to stdout, log files, and any configured log aggregation systems.</p>
<p>**Additionally — login credentials logged at DEBUG level (line 909):**
```typescript
logger.debug("Login request data: " + JSON.stringify(req.body, null, 2));
```</p>
<p>The entire login request body (including cleartext password) is logged at DEBUG level. While DEBUG is typically disabled in production, it is commonly enabled during incident troubleshooting.</p>
<p>No existing CVEs cover sensitive data exposure in logging for OneUptime. CVE-2026-30956 (GHSA-r5v6-2599-9g3m) leaked `resetPasswordToken` from the database via multi-tenant header bypass — this finding is different (token leaked via application logs).</p>
<p>### PoC</p>
<p>**Environment:** OneUptime v10.0.23 via…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4524-cj9j-g4fj"/>
  </entry>
</feed>
