<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:27:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02687</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02687</link>
      <description>bdu:2024-02687</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02687</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-HT81402 — Security fix for CVE-2019-25210 applied in: helm 4.0.1-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ht81402</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: helm&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the helm package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: helm&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the helm package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ht81402</guid>
    </item>
    <item>
      <title>EUVD-2026-161382</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-161382</link>
      <description>EUVD-2026-161382</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-161382</guid>
    </item>
    <item>
      <title>fkie_cve-2019-25210</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-25210</link>
      <description>&lt;p&gt;An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor&amp;#39;s position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values). Also, it is not the Helm Project&amp;#39;s responsibility if a user decides to use --dry-run within a CI/CD environment whose output is visible to unauthorized persons.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor&amp;#39;s position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values). Also, it is not the Helm Project&amp;#39;s responsibility if a user decides to use --dry-run within a CI/CD environment whose output is visible to unauthorized persons.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-25210</guid>
    </item>
    <item>
      <title>Withdrawn: GHSA-jw44-4f3j-q396 — Withdrawn Advisory: Helm shows secrets in clear text</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jw44-4f3j-q396</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: helm.sh/helm/v3&lt;/p&gt;
&lt;p&gt;### Withdrawn Advisory&lt;/p&gt;
&lt;p&gt;This advisory has been withdrawn because the issue describes intended behavior and the output is not exposed to unauthorized users. This link has been maintained to preserve external references.&lt;/p&gt;
&lt;p&gt;### Original Description&lt;/p&gt;
&lt;p&gt;An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor&amp;#39;s position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: helm.sh/helm/v3&lt;/p&gt;
&lt;p&gt;### Withdrawn Advisory&lt;/p&gt;
&lt;p&gt;This advisory has been withdrawn because the issue describes intended behavior and the output is not exposed to unauthorized users. This link has been maintained to preserve external references.&lt;/p&gt;
&lt;p&gt;### Original Description&lt;/p&gt;
&lt;p&gt;An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor&amp;#39;s position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jw44-4f3j-q396</guid>
    </item>
    <item>
      <title>gsd-2019-25210</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-25210</link>
      <description>gsd-2019-25210</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-25210</guid>
    </item>
    <item>
      <title>RHSA-2024:0041 — Red Hat Security Advisory: OpenShift Container Platform 4.16.0 bug fix and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0041</link>
      <description>&lt;p&gt;helm: shows secrets with --dry-run option in clear text opentelemetry: DoS vulnerability in otelhttp golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics ssh: Prefix truncation attack on Binary Packet Protocol (BPP) go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients coredns: CD bit response is cached and served later quic-go: memory exhaustion attack against QUIC&amp;#39;s connection ID mechanism golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm golang: net/mail: comments in display names are incorrectly handled golang: html/template: errors returned from MarshalJSON methods may break template escaping golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks credentials jose: resource exhaustion jose-go: improper handling of highly compressed data follow-redirects: Possible credential leak webpack-dev-middleware: lack of URL validation may lead to file leak&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;helm: shows secrets with --dry-run option in clear text opentelemetry: DoS vulnerability in otelhttp golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics ssh: Prefix truncation attack on Binary Packet Protocol (BPP) go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients coredns: CD bit response is cached and served later quic-go: memory exhaustion attack against QUIC&amp;#39;s connection ID mechanism golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm golang: net/mail: comments in display names are incorrectly handled golang: html/template: errors returned from MarshalJSON methods may break template escaping golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks credentials jose: resource exhaustion jose-go: improper handling of highly compressed data follow-redirects: Possible credential leak webpack-dev-middleware: lack of URL validation may lead to file leak&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0041</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1474 — Red Hat OpenShift Container Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1474</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen offenzulegen oder Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen offenzulegen oder Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1474</guid>
    </item>
  </channel>
</rss>
