<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:03:23 +0000</lastBuildDate>
    <item>
      <title>BIT-openbao-2025-62705 — OpenBao and Vault Leak []byte Fields in Audit Logs</title>
      <link>https://cve.radiocsirt.org/vuln/bit-openbao-2025-62705</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: openbao&lt;/p&gt;
&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao&amp;#39;s audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use of encoding=base64, all data would be emitted unredacted to the audit log, and Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log. This issue has been patched in OpenBao 2.4.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: openbao&lt;/p&gt;
&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao&amp;#39;s audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use of encoding=base64, all data would be emitted unredacted to the audit log, and Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log. This issue has been patched in OpenBao 2.4.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-openbao-2025-62705</guid>
    </item>
    <item>
      <title>EUVD-2026-256718</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-256718</link>
      <description>EUVD-2026-256718</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-256718</guid>
    </item>
    <item>
      <title>fkie_cve-2025-62705</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-62705</link>
      <description>&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao&amp;#39;s audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use of encoding=base64, all data would be emitted unredacted to the audit log, and Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log. This issue has been patched in OpenBao 2.4.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao&amp;#39;s audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use of encoding=base64, all data would be emitted unredacted to the audit log, and Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log. This issue has been patched in OpenBao 2.4.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-62705</guid>
    </item>
    <item>
      <title>GHSA-rc54-2g2c-g36g — OpenBao and Vault Leak []byte Fields in Audit Logs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rc54-2g2c-g36g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openbao/openbao&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;OpenBao&amp;#39;s audit log did not appropriately redact fields when relevant subsystems sent `[]byte` response parameters rather than `string`s. This includes, but is not limited to:&lt;/p&gt;
&lt;p&gt;- `sys/raw` with use of `encoding=base64`, all data would be emitted unredacted to the audit log.
- Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log.&lt;/p&gt;
&lt;p&gt;Third-party plugins may be affected.&lt;/p&gt;
&lt;p&gt;This issue has been present since HashiCorp Vault and continues to impact Vault as of v1.20.4.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;OpenBao v2.4.2 will patch this issue.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If users do not use the above functionality, they are not impacted. To prohibit the use of `sys/raw` globally, ensure `raw_storage_endpoint=false` is set or missing from the server configuration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openbao/openbao&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;OpenBao&amp;#39;s audit log did not appropriately redact fields when relevant subsystems sent `[]byte` response parameters rather than `string`s. This includes, but is not limited to:&lt;/p&gt;
&lt;p&gt;- `sys/raw` with use of `encoding=base64`, all data would be emitted unredacted to the audit log.
- Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log.&lt;/p&gt;
&lt;p&gt;Third-party plugins may be affected.&lt;/p&gt;
&lt;p&gt;This issue has been present since HashiCorp Vault and continues to impact Vault as of v1.20.4.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;OpenBao v2.4.2 will patch this issue.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If users do not use the above functionality, they are not impacted. To prohibit the use of `sys/raw` globally, ensure `raw_storage_endpoint=false` is set or missing from the server configuration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rc54-2g2c-g36g</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15663-1 — openbao-2.4.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15663-1</link>
      <description>&lt;p&gt;openbao-2.4.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openbao-2.4.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15663-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2391 — OpenBao: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2391</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenBao ausnutzen, um Informationen offenzulegen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenBao ausnutzen, um Informationen offenzulegen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2391</guid>
    </item>
  </channel>
</rss>
