<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T01:15:56.166195+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342181</id>
    <title>EUVD-2026-342181</title>
    <updated>2026-10-06T01:15:56.212193+00:00</updated>
    <content>EUVD-2026-342181</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342181"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47768</id>
    <title>fkie_cve-2026-47768</title>
    <updated>2026-10-06T01:15:56.212236+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47768"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9pg3-25fq-p6cc</id>
    <title>GHSA-9pg3-25fq-p6cc — nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)</title>
    <updated>2026-10-06T01:15:56.212280+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/juev/nebula-mesh</p>
<p>`internal/web/operators.go:251` — after `handleOperatorCreateAPIKey` mints a fresh 32-byte bearer token, the redirect points the operator's browser at:</p>
<p>/ui/operators/&lt;id&gt;?new_key=&lt;raw-token&gt;&amp;key_name=&lt;name&gt;</p>
<p>The raw API key ends up:
- in the browser's URL history
- in the `Referer` header on every cross-origin asset the detail page loads (any third-party SVG/CSS/JS resource the layout pulls in)
- in any reverse-proxy or load-balancer access log on the path (nginx default `combined` log captures the query string)
- in any structured log sink the operator's local browser-history backup tool ships out</p>
<p>`Authorization: Bearer &lt;token&gt;` headers go through the same hops without these problems because access logs typically don't capture request headers and the browser doesn't replay headers cross-origin.</p>
<p>Same handler also appends `name` (`r.FormValue("name")`) to the query string without `url.QueryEscape`, so an `&amp;` in the operator-supplied key name corrupts query parsing and a `\r\n` in older proxies could split response headers.</p>
<p>## Affected
All released versions up to v0.3.1.</p>
<p>## Reproducer
As admin, create an API key via `/ui/operators/&lt;id&gt;/api-keys` (form POST). The 303 Location header carries the raw token in the query string. Open browser DevTools → Network → response headers; or check the reverse-proxy access log; or check the operator-detail page's `Referer`-emitting fetches.</p>
<p>## Suggested fix
Stash the raw key in a one-shot server-side flash storage (e.g., a row in `…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9pg3-25fq-p6cc"/>
  </entry>
</feed>
