<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:43:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-15587</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15587</link>
      <description>bdu:2025-15587</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15587</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0199 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</link>
      <description>certfr-2026-avi-0199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AY71406 — Security fixes in tempo-fips 2.9.1-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay71406</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tempo-fips&lt;/p&gt;
&lt;p&gt;Package tempo-fips version 2.9.1-r0 fixes 20 vulnerabilities: CVE-2026-33186, CVE-2025-47914, CVE-2025-58181, CVE-2025-47913, CVE-2026-32287...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tempo-fips&lt;/p&gt;
&lt;p&gt;Package tempo-fips version 2.9.1-r0 fixes 20 vulnerabilities: CVE-2026-33186, CVE-2025-47914, CVE-2025-58181, CVE-2025-47913, CVE-2026-32287...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ay71406</guid>
    </item>
    <item>
      <title>EUVD-2026-331231</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331231</link>
      <description>EUVD-2026-331231</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331231</guid>
    </item>
    <item>
      <title>fkie_cve-2025-11065</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-11065</link>
      <description>&lt;p&gt;A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-11065</guid>
    </item>
    <item>
      <title>GHSA-2464-8j7c-4cjm — go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2464-8j7c-4cjm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-viper/mapstructure/v2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Use of this library in a security-critical context may result in leaking sensitive information, if used to process sensitive fields.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;OpenBao (and presumably HashiCorp Vault) have surfaced error messages from `mapstructure` as follows:&lt;/p&gt;
&lt;p&gt;https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L43-L50&lt;/p&gt;
&lt;p&gt;```go
			_, _, err := d.getPrimitive(field, schema)
			if err != nil {
				return fmt.Errorf(&amp;#34;error converting input for field %q: %w&amp;#34;, field, err)
			}
```&lt;/p&gt;
&lt;p&gt;where this calls `mapstructure.WeakDecode(...)`: https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L181-L193&lt;/p&gt;
&lt;p&gt;```go&lt;/p&gt;
&lt;p&gt;func (d *FieldData) getPrimitive(k string, schema *FieldSchema) (interface{}, bool, error) {
	raw, ok := d.Raw[k]
	if !ok {
		return nil, false, nil
	}&lt;/p&gt;
&lt;p&gt;switch t := schema.Type; t {
	case TypeBool:
		var result bool
		if err := mapstructure.WeakDecode(raw, &amp;amp;result); err != nil {
			return nil, false, err
		}
		return result, true, nil
```&lt;/p&gt;
&lt;p&gt;Notably, `WeakDecode(...)` eventually calls one of the decode helpers, which surfaces the original value via `strconv` helpers:&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L720-L727&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L791-L798&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-viper/mapstructure/v2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Use of this library in a security-critical context may result in leaking sensitive information, if used to process sensitive fields.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;OpenBao (and presumably HashiCorp Vault) have surfaced error messages from `mapstructure` as follows:&lt;/p&gt;
&lt;p&gt;https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L43-L50&lt;/p&gt;
&lt;p&gt;```go
			_, _, err := d.getPrimitive(field, schema)
			if err != nil {
				return fmt.Errorf(&amp;#34;error converting input for field %q: %w&amp;#34;, field, err)
			}
```&lt;/p&gt;
&lt;p&gt;where this calls `mapstructure.WeakDecode(...)`: https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L181-L193&lt;/p&gt;
&lt;p&gt;```go&lt;/p&gt;
&lt;p&gt;func (d *FieldData) getPrimitive(k string, schema *FieldSchema) (interface{}, bool, error) {
	raw, ok := d.Raw[k]
	if !ok {
		return nil, false, nil
	}&lt;/p&gt;
&lt;p&gt;switch t := schema.Type; t {
	case TypeBool:
		var result bool
		if err := mapstructure.WeakDecode(raw, &amp;amp;result); err != nil {
			return nil, false, err
		}
		return result, true, nil
```&lt;/p&gt;
&lt;p&gt;Notably, `WeakDecode(...)` eventually calls one of the decode helpers, which surfaces the original value via `strconv` helpers:&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L720-L727&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L791-L798&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2464-8j7c-4cjm</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15610-1 — grafana-11.6.6-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15610-1</link>
      <description>&lt;p&gt;grafana-11.6.6-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana-11.6.6-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15610-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21137-1 — Security update for alloy</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21137-1</link>
      <description>&lt;p&gt;Security update for alloy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for alloy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21137-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-11065</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-11065</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: golang-github-go-viper-mapstructure, Ubuntu:26.04:LTS: golang-github-go-viper-mapstructure&lt;/p&gt;
&lt;p&gt;A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: golang-github-go-viper-mapstructure, Ubuntu:26.04:LTS: golang-github-go-viper-mapstructure&lt;/p&gt;
&lt;p&gt;A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-11065</guid>
    </item>
  </channel>
</rss>
