<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:12:59.062217+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06624</id>
    <title>bdu:2026-06624</title>
    <updated>2026-10-02T12:12:59.170436+00:00</updated>
    <content>bdu:2026-06624</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06624"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-eh36582</id>
    <title>Withdrawn: CLEANSTART-2026-EH36582 — Security fixes for CVE-2025-47912, CVE-2025-55190, CVE-2025-55191, CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-…</title>
    <updated>2026-10-02T12:12:59.170485+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: argo-cd</p>
<p>Multiple security vulnerabilities affect the argo-cd package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-eh36582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364308</id>
    <title>EUVD-2026-364308</title>
    <updated>2026-10-02T12:12:59.170537+00:00</updated>
    <content>EUVD-2026-364308</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364308"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42880</id>
    <title>fkie_cve-2026-42880</title>
    <updated>2026-10-02T12:12:59.170557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42880"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3v3m-wc6v-x4x3</id>
    <title>GHSA-3v3m-wc6v-x4x3 — ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction</title>
    <updated>2026-10-02T12:12:59.170592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/argoproj/argo-cd/v3</p>
<p>### Summary
There is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism.</p>
<p>### Details
Argo CD masks Secret data in every endpoint that returns Kubernetes resource state except one. All the other endpoints such as GetManifests, GetManifestsWithFiles, GetResource and PatchResource utilize hideSecretData() to mask the returned secret value. The vulnerable function ServerSideDiff gRPC/REST endpoint (/application.ApplicationService/ServerSideDiff) constructs its response with raw, unmasked PredictedLive and NormalizedLive states:</p>
<p>```
// server/application/application.go:3051-3062
responseDiffs = append(responseDiffs, &amp;v1alpha1.ResourceDiff{
    TargetState:     string(diffRes.PredictedLive),
    LiveState:       string(diffRes.NormalizedLive),
})
```</p>
<p>A user only requires RBAC to call this ServerSideDiff function. Every authenticated Argo CD user has get access via the default role:catch-all policy. However, Argo CD has a defense layer called removeWebhookMutation() that normally strips non-Argo CD-managed fields from the Server Side Apply (SSA) dry-run response and merges them with the client-provided (masked) live state. This prevents real Secret values from leaking through the diff. However, this defense is entirely skipped when the Application has the annotation argocd.argoproj.i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3v3m-wc6v-x4x3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2026:12433</id>
    <title>RHBA-2026:12433 — Red Hat Bug Fix Advisory: Red Hat OpenShift GitOps v1.20.3 bug fix and enhancement update</title>
    <updated>2026-10-02T12:12:59.170717+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>argoproj/argo-cd: Argo CD: Information disclosure of Kubernetes Secret data via Server-Side Apply dry-run mechanism</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2026:12433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1383</id>
    <title>WID-SEC-W-2026-1383 — Argo CD: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-02T12:12:59.170745+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Argo CD ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1383"/>
  </entry>
</feed>
