<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:58:42 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-08724</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-08724</link>
      <description>bdu:2026-08724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-08724</guid>
    </item>
    <item>
      <title>BIT-openbao-2026-39946 — OpenBao allows SQL Injection in PostgreSQL database secrets engine</title>
      <link>https://cve.radiocsirt.org/vuln/bit-openbao-2026-39946</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: openbao&lt;/p&gt;
&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: openbao&lt;/p&gt;
&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-openbao-2026-39946</guid>
    </item>
    <item>
      <title>EUVD-2026-292189</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292189</link>
      <description>EUVD-2026-292189</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292189</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39946</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39946</link>
      <description>&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user. This vulnerability was original from HashiCorp Vault. The vulnerability is addressed in v2.5.3. As a workaround, audit table schemas and ensure database users cannot create new schemas and grant privileges on them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39946</guid>
    </item>
    <item>
      <title>GHSA-6vgr-cp5c-ffx3 — OpenBao's SQL Injection in PostgreSQL database secrets engine</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6vgr-cp5c-ffx3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openbao/openbao&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user.&lt;/p&gt;
&lt;p&gt;This vulnerability was originally from HashiCorp Vault.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This was addressed in v2.5.3.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Audit table schemas and ensure database users cannot create new schemas and grant privileges on them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openbao/openbao&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user.&lt;/p&gt;
&lt;p&gt;This vulnerability was originally from HashiCorp Vault.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This was addressed in v2.5.3.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Audit table schemas and ensure database users cannot create new schemas and grant privileges on them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6vgr-cp5c-ffx3</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10594-1 — openbao-2.5.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10594-1</link>
      <description>&lt;p&gt;openbao-2.5.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openbao-2.5.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10594-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1189 — OpenBao: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1189</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenBao ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, und um einen SQL-Injection Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenBao ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, und um einen SQL-Injection Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1189</guid>
    </item>
  </channel>
</rss>
