<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T10:45:17.230075+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318999</id>
    <title>EUVD-2026-318999</title>
    <updated>2026-10-06T10:45:17.232372+00:00</updated>
    <content>EUVD-2026-318999</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44516</id>
    <title>fkie_cve-2026-44516</title>
    <updated>2026-10-06T10:45:17.232402+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls made via Spring's RestClient and logs the full request body, response body, and response headers. When an error response is received, this information is included in the thrown HttpClientErrorException message, which is logged at ERROR level by Spring's default exception handling — regardless of the application's DEBUG log level setting. This vulnerability is fixed in 12.33.0 and 13.26.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44516"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3jh5-rr2q-xfv7</id>
    <title>GHSA-3jh5-rr2q-xfv7 — Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer</title>
    <updated>2026-10-06T10:45:17.232438+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.ritense.valtimo:web</p>
<p>### Summary</p>
<p>The `LoggingRestClientCustomizer` in the `web` module automatically intercepts all outgoing HTTP calls made via Spring's `RestClient` and logs the full request body, response body, and response headers. When an error response is received, this information is included in the thrown `HttpClientErrorException` message, which is logged at ERROR level by Spring's default exception handling — regardless of the application's DEBUG log level setting.</p>
<p>### Impact</p>
<p>The logged data can contain highly sensitive information including:
- Authentication credentials (JWT tokens, API keys, OAuth tokens) in request bodies or response headers
- Personal data (BSN, email addresses, case details) in request/response bodies
- Session tokens in `Set-Cookie` response headers</p>
<p>This data is exposed to:
- Anyone with access to application logs (stdout/log files)
- Users with access to logging aggregation tools (e.g. Grafana/Loki)
- Any Valtimo user with the admin role, through the built-in logging module (since Valtimo 12.5.0)</p>
<p>Leaked authentication credentials could be used to impersonate the Valtimo application against the target external API (e.g. ZGW services), compromising that API's security boundary.</p>
<p>Related: GHSA-hfrg-mcvw-8mch (similar sensitive data exposure in InboxHandlingService)</p>
<p>### Affected Code</p>
<p>`com.ritense.valtimo.web.logging.LoggingRestClientCustomizer#intercept` in the `web` module.</p>
<p>### Patched Versions</p>
<p>The vulnerability is fixed in:
- **12.33.0** (v12 release line…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3jh5-rr2q-xfv7"/>
  </entry>
</feed>
