<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T01:58:24.671167+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336096</id>
    <title>EUVD-2026-336096</title>
    <updated>2026-10-06T01:58:24.726566+00:00</updated>
    <content>EUVD-2026-336096</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59155</id>
    <title>fkie_cve-2026-59155</title>
    <updated>2026-10-06T01:58:24.726610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&amp;M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API credentials, including Cloudflare API tokens, TencentCloud SecretKeys, Slack, Discord, and Telegram webhook URLs with embedded bot tokens, and Authorization header values, without any field-level redaction. Any authenticated admin or PAT with nezha:ddns:read or nezha:notification:read scope can receive stored credentials through the listDDNS and listNotification handlers in a single API response. This issue is fixed in version 2.2.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ww5p-j6cj-6mqq</id>
    <title>GHSA-ww5p-j6cj-6mqq — Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API</title>
    <updated>2026-10-06T01:58:24.726649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/nezhahq/nezha</p>
<p>### Summary</p>
<p>The `GET /api/v1/ddns` and `GET /api/v1/notification` endpoints return full resource objects including plaintext third-party API credentials — Cloudflare API tokens, TencentCloud SecretKeys, Slack/Discord/Telegram webhook URLs with embedded bot tokens, and Authorization header values — without any field-level redaction. Any authenticated admin who calls these endpoints receives every stored credential in the system in a single API response. A compromised admin session or leaked PAT with `nezha:ddns:read` or `nezha:notification:read` scope exposes all third-party integration secrets.</p>
<p>### Details</p>
<p>The `listDDNS` and `listNotification` handlers follow an identical pattern: they call the corresponding singleton `GetSortedList()`, `copier.Copy` the full in-memory structs into a response slice, and return them via `listHandler` with zero field stripping.</p>
<p>**DDNS — `cmd/dashboard/controller/ddns.go:25–33`:**</p>
<p>```go
func listDDNS(c *gin.Context) ([]*model.DDNSProfile, error) {
    var ddnsProfiles []*model.DDNSProfile
    list := singleton.DDNSShared.GetSortedList()
    if err := copier.Copy(&amp;ddnsProfiles, &amp;list); err != nil {
        return nil, err
    }
    return ddnsProfiles, nil
}
```</p>
<p>The `DDNSProfile` struct (`model/ddns.go:20–36`) serializes `AccessSecret` with `json:"access_secret,omitempty"` — non-empty Cloudflare tokens and TencentCloud SecretKeys are returned in cleartext. The `WebhookURL` and `WebhookHeaders` fields may also contain embedded secrets.</p>
<p>**N…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ww5p-j6cj-6mqq"/>
  </entry>
</feed>
