<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:52:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-14350</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14350</link>
      <description>bdu:2025-14350</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14350</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AC12204 — go-git is a highly extensible git implementation library written in pure Go</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ac12204</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-cd-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the argo-cd-fips package. go-git is a highly extensible git implementation library written in pure Go. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-cd-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the argo-cd-fips package. go-git is a highly extensible git implementation library written in pure Go. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ac12204</guid>
    </item>
    <item>
      <title>EUVD-2026-252074</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-252074</link>
      <description>EUVD-2026-252074</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-252074</guid>
    </item>
    <item>
      <title>fkie_cve-2025-55190</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55190</link>
      <description>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets. This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`. This issue is fixed in versions 2.13.9, 2.14.16, 3.0.14 and 3.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets. This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`. This issue is fixed in versions 2.13.9, 2.14.16, 3.0.14 and 3.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-55190</guid>
    </item>
    <item>
      <title>GHSA-786q-9hcg-v9ff — Argo CD's Project API Token Exposes Repository Credentials</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-786q-9hcg-v9ff</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v2, Go: github.com/argoproj/argo-cd/v3&lt;/p&gt;
&lt;p&gt;### Summary
Argo CD API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets.&lt;/p&gt;
&lt;p&gt;Component: `Project API (/api/v1/projects/{project}/detailed)`&lt;/p&gt;
&lt;p&gt;## Vulnerability Details
### Expected Behavior
API tokens should require explicit permission to access sensitive credential information. Standard project permissions should not grant access to repository secrets.
### Actual Behavior
API tokens with basic project permissions can retrieve all repository credentials associated with a project through the detailed project API endpoint.&lt;/p&gt;
&lt;p&gt;**Note**: This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`&lt;/p&gt;
&lt;p&gt;### Steps to Reproduce&lt;/p&gt;
&lt;p&gt;1. Create an API token with the following project-level permissions:
  ```
  p, proj:myProject:project-automation-role, applications, sync, myProject/*, allow
  p, proj:myProject:project-automation-role, applications, action/argoproj.io/Rollout/*, myProject/*, allow
  p, proj:myProject:project-automation-role, applications, get, myProject/*, allow
  ```&lt;/p&gt;
&lt;p&gt;2. Call the project details API:
  ```
  bashcurl -sH &amp;#34;Authorization: Bearer $ARGOCD_API_TOKEN&amp;#34; \
    &amp;#34;https://argocd.example.com/api/v1/projects/myProject/detaile…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v2, Go: github.com/argoproj/argo-cd/v3&lt;/p&gt;
&lt;p&gt;### Summary
Argo CD API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application management permissions and no explicit access to secrets.&lt;/p&gt;
&lt;p&gt;Component: `Project API (/api/v1/projects/{project}/detailed)`&lt;/p&gt;
&lt;p&gt;## Vulnerability Details
### Expected Behavior
API tokens should require explicit permission to access sensitive credential information. Standard project permissions should not grant access to repository secrets.
### Actual Behavior
API tokens with basic project permissions can retrieve all repository credentials associated with a project through the detailed project API endpoint.&lt;/p&gt;
&lt;p&gt;**Note**: This vulnerability does not only affect project-level permissions. Any token with project get permissions is also vulnerable, including global permissions such as: `p, role/user, projects, get, *, allow`&lt;/p&gt;
&lt;p&gt;### Steps to Reproduce&lt;/p&gt;
&lt;p&gt;1. Create an API token with the following project-level permissions:
  ```
  p, proj:myProject:project-automation-role, applications, sync, myProject/*, allow
  p, proj:myProject:project-automation-role, applications, action/argoproj.io/Rollout/*, myProject/*, allow
  p, proj:myProject:project-automation-role, applications, get, myProject/*, allow
  ```&lt;/p&gt;
&lt;p&gt;2. Call the project details API:
  ```
  bashcurl -sH &amp;#34;Authorization: Bearer $ARGOCD_API_TOKEN&amp;#34; \
    &amp;#34;https://argocd.example.com/api/v1/projects/myProject/detaile…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-786q-9hcg-v9ff</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15538-1 — govulncheck-vulndb-0.0.20250908T141310-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15538-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250908T141310-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250908T141310-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15538-1</guid>
    </item>
    <item>
      <title>RHSA-2025:15387 — Red Hat Security Advisory: Red Hat OpenShift GitOps security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:15387</link>
      <description>&lt;p&gt;github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:15387</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1978 — Red Hat OpenShift GitOps (Argo CD): Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1978</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift GitOps (Argo CD) ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift GitOps (Argo CD) ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1978</guid>
    </item>
  </channel>
</rss>
