<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T03:07:16.645727+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2023-30610</id>
    <title>CVE-2023-30610 — AWS SDK for Rust will log AWS credentials when TRACE-level logging is enabled for request sending</title>
    <updated>2026-10-08T03:07:16.647462+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> awslabs aws-sdk-rust</p>
<p>aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access key, AWS secret key, and security token in plaintext. When TRACE-level logging is enabled for an SDK, `SigningParams` is printed, thereby revealing those credentials to anyone with access to logs. All users of the AWS SDK for Rust who enabled TRACE-level logging, either globally (e.g. `RUST_LOG=trace`), or for the `aws-sigv4` crate specifically are affected. This issue has been addressed in a set of new releases. Users are advised to upgrade. Users unable to upgrade should disable TRACE-level logging for AWS Rust SDK crates.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2023-30610"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mjv9-vp6w-3rc9</id>
    <title>GHSA-mjv9-vp6w-3rc9 — AWS SDK for Rust will log AWS credentials when TRACE-level logging is enabled for request sending</title>
    <updated>2026-10-08T03:07:16.647528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: aws-sigv4</p>
<p>The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access key, AWS secret key, and security token in plaintext. When TRACE-level logging is enabled for an SDK, `SigningParams` is printed, thereby revealing those credentials to anyone with access to logs.</p>
<p>### Impact
All users of the AWS SDK for Rust who enabled TRACE-level logging, either globally (e.g. `RUST_LOG=trace`), or for the `aws-sigv4` crate specifically.</p>
<p>### Patches
- Versions &gt;= `0.55.1`
- `0.54.2`
- `0.53.2`
- `0.52.1`
- `0.51.1`
- `0.50.1`
- `0.49.1`
- `0.48.1`
- `0.47.1`
- `0.46.1`
- `0.15.1`
- `0.14.1`
- `0.13.1`
- `0.12.1`
- `0.11.1`
- `0.10.2`
- `0.9.1`
- `0.8.1`
- `0.7.1`
- `0.6.1`
- `0.5.3`
- `0.3.1`
- `0.2.1`</p>
<p>### Workarounds
Disable TRACE-level logging for AWS Rust SDK crates.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mjv9-vp6w-3rc9"/>
  </entry>
</feed>
