<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:18:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-263985</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-263985</link>
      <description>EUVD-2026-263985</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-263985</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68429</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68429</link>
      <description>&lt;p&gt;Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions 7.6.21, 8.6.15, 9.1.17, and 10.1.10 relates to Storybook’s handling of environment variables defined in a `.env` file, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by the `storybook build` command. When a built Storybook is published to the web, the bundle’s source is viewable, thus potentially exposing those variables to anyone with access. For a project to potentially be vulnerable to this issue, it must build the Storybook (i.e. run `storybook build` directly or indirectly) in a directory that contains a `.env` file (including variants like `.env.local`) and publish the built Storybook to the web. Storybooks built without a `.env` file at build time are not affected, including common CI-based builds where secrets are provided via platform environment variables rather than `.env` files. Storybook runtime environments (i.e. `storybook dev`) are not affected. Deployed applications that share a repo with your Storybook are not affected. Users should upgrade their Storybook—on both their local machines and CI environment—to version .6.21, 8.6.15, 9.1.17, or 10.1.10 as soon as possible. Maintainers additionally recommend that users audit for any sensitive secrets provided via `.env` files and rotate those keys. Some projects may have been r…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions 7.6.21, 8.6.15, 9.1.17, and 10.1.10 relates to Storybook’s handling of environment variables defined in a `.env` file, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by the `storybook build` command. When a built Storybook is published to the web, the bundle’s source is viewable, thus potentially exposing those variables to anyone with access. For a project to potentially be vulnerable to this issue, it must build the Storybook (i.e. run `storybook build` directly or indirectly) in a directory that contains a `.env` file (including variants like `.env.local`) and publish the built Storybook to the web. Storybooks built without a `.env` file at build time are not affected, including common CI-based builds where secrets are provided via platform environment variables rather than `.env` files. Storybook runtime environments (i.e. `storybook dev`) are not affected. Deployed applications that share a repo with your Storybook are not affected. Users should upgrade their Storybook—on both their local machines and CI environment—to version .6.21, 8.6.15, 9.1.17, or 10.1.10 as soon as possible. Maintainers additionally recommend that users audit for any sensitive secrets provided via `.env` files and rotate those keys. Some projects may have been r…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68429</guid>
    </item>
    <item>
      <title>GHSA-8452-54wp-rmv6 — Storybook manager bundle may expose environment variables during build</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8452-54wp-rmv6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: storybook&lt;/p&gt;
&lt;p&gt;On December 11th, the Storybook team received a responsible disclosure alerting them to a potential vulnerability in certain built and published Storybooks.&lt;/p&gt;
&lt;p&gt;The vulnerability is a bug in how Storybook handles environment variables defined in a `.env` file, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by the `storybook build` command. When a built Storybook is published to the web, the bundle’s source is viewable, thus potentially exposing those variables to anyone with access. If those variables contained secrets, they should be considered compromised.&lt;/p&gt;
&lt;p&gt;## Who is impacted?&lt;/p&gt;
&lt;p&gt;For a project to be vulnerable to this issue, it must:&lt;/p&gt;
&lt;p&gt;- Build the Storybook (i.e. run `storybook build` directly or indirectly) in a directory that contains a `.env` file (including variants like `.env.local`)
- The `.env` file contains sensitive secrets
- Use Storybook version `7.0.0` or above
- Publish the built Storybook to the web&lt;/p&gt;
&lt;p&gt;Storybooks built without a `.env` file at build time are not affected, including common CI-based builds where secrets are provided via platform environment variables rather than `.env` files.&lt;/p&gt;
&lt;p&gt;Users&amp;#39; Storybook runtime environments (i.e. `storybook dev`) are not affected. Deployed applications that share a repo with a project&amp;#39;s Storybook are not affected.&lt;/p&gt;
&lt;p&gt;Storybook 6 and below are not affected.&lt;/p&gt;
&lt;p&gt;## Recommended actions&lt;/p&gt;
&lt;p&gt;First, Storybook recommends that everyone audit for any sensitive secrets provid…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: storybook&lt;/p&gt;
&lt;p&gt;On December 11th, the Storybook team received a responsible disclosure alerting them to a potential vulnerability in certain built and published Storybooks.&lt;/p&gt;
&lt;p&gt;The vulnerability is a bug in how Storybook handles environment variables defined in a `.env` file, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by the `storybook build` command. When a built Storybook is published to the web, the bundle’s source is viewable, thus potentially exposing those variables to anyone with access. If those variables contained secrets, they should be considered compromised.&lt;/p&gt;
&lt;p&gt;## Who is impacted?&lt;/p&gt;
&lt;p&gt;For a project to be vulnerable to this issue, it must:&lt;/p&gt;
&lt;p&gt;- Build the Storybook (i.e. run `storybook build` directly or indirectly) in a directory that contains a `.env` file (including variants like `.env.local`)
- The `.env` file contains sensitive secrets
- Use Storybook version `7.0.0` or above
- Publish the built Storybook to the web&lt;/p&gt;
&lt;p&gt;Storybooks built without a `.env` file at build time are not affected, including common CI-based builds where secrets are provided via platform environment variables rather than `.env` files.&lt;/p&gt;
&lt;p&gt;Users&amp;#39; Storybook runtime environments (i.e. `storybook dev`) are not affected. Deployed applications that share a repo with a project&amp;#39;s Storybook are not affected.&lt;/p&gt;
&lt;p&gt;Storybook 6 and below are not affected.&lt;/p&gt;
&lt;p&gt;## Recommended actions&lt;/p&gt;
&lt;p&gt;First, Storybook recommends that everyone audit for any sensitive secrets provid…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8452-54wp-rmv6</guid>
    </item>
    <item>
      <title>RHSA-2026:2256 — Red Hat Security Advisory: Red Hat multicluster global hub 1.5.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:2256</link>
      <description>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications qs: qs: Denial of Service via improper input validation in array parsing urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data Storybook: Storybook: Information disclosure via unexpected bundling of environment variables urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications qs: qs: Denial of Service via improper input validation in array parsing urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data Storybook: Storybook: Information disclosure via unexpected bundling of environment variables urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:2256</guid>
    </item>
  </channel>
</rss>
