<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:40:02 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:34357 — Important: opentelemetry-collector security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:34357</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: opentelemetry-collector&lt;/p&gt;
&lt;p&gt;Collector with the supported components for a AlmaLinux build of OpenTelemetry&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)
  * github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)
  * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  * golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
  * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
  * crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: opentelemetry-collector&lt;/p&gt;
&lt;p&gt;Collector with the supported components for a AlmaLinux build of OpenTelemetry&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)
  * github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)
  * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  * golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
  * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
  * crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:34357</guid>
    </item>
    <item>
      <title>BIT-prometheus-2026-42151 — Prometheus Azure AD remote write OAuth client secret exposed via config API</title>
      <link>https://cve.radiocsirt.org/vuln/bit-prometheus-2026-42151</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: prometheus&lt;/p&gt;
&lt;p&gt;Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: prometheus&lt;/p&gt;
&lt;p&gt;Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-prometheus-2026-42151</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AP95632 — Security fixes for CVE-2026-25679, CVE-2026-27139, CVE-2026-27142, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ap95632</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: keda-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the keda-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: keda-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the keda-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ap95632</guid>
    </item>
    <item>
      <title>EUVD-2026-366101</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366101</link>
      <description>EUVD-2026-366101</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366101</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42151</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42151</link>
      <description>&lt;p&gt;Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42151</guid>
    </item>
    <item>
      <title>GHSA-wg65-39gg-5wfj — Prometheus Azure AD remote write OAuth client secret exposed via config API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wg65-39gg-5wfj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/prometheus/prometheus&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Users who use Azure AD remote write with OAuth authentication are impacted.&lt;/p&gt;
&lt;p&gt;The `client_secret` field in the Azure AD remote write OAuth configuration (`storage/remote/azuread`) was typed as `string` instead of `Secret`. Prometheus redacts fields of type `Secret` when serving the configuration via the `/-/config` HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The problem has been patched by changing `ClientSecret` in `OAuthConfig` to `Secret`. Users should upgrade to 3.11.3 or 3.5.3 LTS.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users  who can not upgrade can switch to Managed Identity or Workload Identity authentication for Azure AD remote write, which do not involve a client secret.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/prometheus/prometheus&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Users who use Azure AD remote write with OAuth authentication are impacted.&lt;/p&gt;
&lt;p&gt;The `client_secret` field in the Azure AD remote write OAuth configuration (`storage/remote/azuread`) was typed as `string` instead of `Secret`. Prometheus redacts fields of type `Secret` when serving the configuration via the `/-/config` HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The problem has been patched by changing `ClientSecret` in `OAuthConfig` to `Secret`. Users should upgrade to 3.11.3 or 3.5.3 LTS.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users  who can not upgrade can switch to Managed Identity or Workload Identity authentication for Azure AD remote write, which do not involve a client secret.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wg65-39gg-5wfj</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-42151 — Prometheus Azure AD remote write OAuth client secret exposed via config API</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42151</link>
      <description>msrc_CVE-2026-42151</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-42151</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10676-1 — golang-github-prometheus-prometheus-3.11.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10676-1</link>
      <description>&lt;p&gt;golang-github-prometheus-prometheus-3.11.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang-github-prometheus-prometheus-3.11.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10676-1</guid>
    </item>
    <item>
      <title>RHSA-2026:25039 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:25039</link>
      <description>&lt;p&gt;github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression python-idna: idna: Denial of Service via specially crafted long inputs joserfc: joserfc: Resource exhaustion via oversized JSON Web Signature (JWS) payloads&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression python-idna: idna: Denial of Service via specially crafted long inputs joserfc: joserfc: Resource exhaustion via oversized JSON Web Signature (JWS) payloads&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:25039</guid>
    </item>
    <item>
      <title>RLSA-2026:34357 — Important: opentelemetry-collector security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:34357</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: opentelemetry-collector&lt;/p&gt;
&lt;p&gt;Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)&lt;/p&gt;
&lt;p&gt;* github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)&lt;/p&gt;
&lt;p&gt;* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)&lt;/p&gt;
&lt;p&gt;* crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: opentelemetry-collector&lt;/p&gt;
&lt;p&gt;Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)&lt;/p&gt;
&lt;p&gt;* github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)&lt;/p&gt;
&lt;p&gt;* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)&lt;/p&gt;
&lt;p&gt;* crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:34357</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:2774-1 — Security update 5.1.4 for Multi-Linux Manager Server</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:2774-1</link>
      <description>&lt;p&gt;Security update 5.1.4 for Multi-Linux Manager Server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update 5.1.4 for Multi-Linux Manager Server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:2774-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-42151</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42151</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: prometheus, Ubuntu:18.04:LTS: prometheus, Ubuntu:20.04:LTS: prometheus, Ubuntu:Pro:22.04:LTS: prometheus, Ubuntu:Pro:24.04:LTS: prometheus, Ubuntu:25.10: prometheus, Ubuntu:Pro:26.04:LTS: prometheus&lt;/p&gt;
&lt;p&gt;Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: prometheus, Ubuntu:18.04:LTS: prometheus, Ubuntu:20.04:LTS: prometheus, Ubuntu:Pro:22.04:LTS: prometheus, Ubuntu:Pro:24.04:LTS: prometheus, Ubuntu:25.10: prometheus, Ubuntu:Pro:26.04:LTS: prometheus&lt;/p&gt;
&lt;p&gt;Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42151</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1292 — Prometheus: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1292</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Prometheus ausnutzen, um einen Denial of Service Angriff durchzuführen, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Prometheus ausnutzen, um einen Denial of Service Angriff durchzuführen, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1292</guid>
    </item>
  </channel>
</rss>
