<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:37:04 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06624</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06624</link>
      <description>bdu:2026-06624</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06624</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EH36582 — Security fixes for CVE-2025-47912, CVE-2025-55190, CVE-2025-55191, CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-eh36582</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-cd&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the argo-cd package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-cd&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the argo-cd package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-eh36582</guid>
    </item>
    <item>
      <title>EUVD-2026-364308</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364308</link>
      <description>EUVD-2026-364308</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364308</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42880</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42880</link>
      <description>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD&amp;#39;s ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server&amp;#39;s Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD&amp;#39;s ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server&amp;#39;s Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42880</guid>
    </item>
    <item>
      <title>GHSA-3v3m-wc6v-x4x3 — ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3v3m-wc6v-x4x3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v3&lt;/p&gt;
&lt;p&gt;### Summary
There is a missing authorization and data-masking gap in Argo CD&amp;#39;s ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server&amp;#39;s Server-Side Apply dry-run mechanism.&lt;/p&gt;
&lt;p&gt;### Details
Argo CD masks Secret data in every endpoint that returns Kubernetes resource state except one. All the other endpoints such as GetManifests, GetManifestsWithFiles, GetResource and PatchResource utilize hideSecretData() to mask the returned secret value. The vulnerable function ServerSideDiff gRPC/REST endpoint (/application.ApplicationService/ServerSideDiff) constructs its response with raw, unmasked PredictedLive and NormalizedLive states:&lt;/p&gt;
&lt;p&gt;```
// server/application/application.go:3051-3062
responseDiffs = append(responseDiffs, &amp;amp;v1alpha1.ResourceDiff{
    TargetState:     string(diffRes.PredictedLive),
    LiveState:       string(diffRes.NormalizedLive),
})
```&lt;/p&gt;
&lt;p&gt;A user only requires RBAC to call this ServerSideDiff function. Every authenticated Argo CD user has get access via the default role:catch-all policy. However, Argo CD has a defense layer called removeWebhookMutation() that normally strips non-Argo CD-managed fields from the Server Side Apply (SSA) dry-run response and merges them with the client-provided (masked) live state. This prevents real Secret values from leaking through the diff. However, this defense is entirely skipped when the Application has the annotation argocd.argoproj.i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v3&lt;/p&gt;
&lt;p&gt;### Summary
There is a missing authorization and data-masking gap in Argo CD&amp;#39;s ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server&amp;#39;s Server-Side Apply dry-run mechanism.&lt;/p&gt;
&lt;p&gt;### Details
Argo CD masks Secret data in every endpoint that returns Kubernetes resource state except one. All the other endpoints such as GetManifests, GetManifestsWithFiles, GetResource and PatchResource utilize hideSecretData() to mask the returned secret value. The vulnerable function ServerSideDiff gRPC/REST endpoint (/application.ApplicationService/ServerSideDiff) constructs its response with raw, unmasked PredictedLive and NormalizedLive states:&lt;/p&gt;
&lt;p&gt;```
// server/application/application.go:3051-3062
responseDiffs = append(responseDiffs, &amp;amp;v1alpha1.ResourceDiff{
    TargetState:     string(diffRes.PredictedLive),
    LiveState:       string(diffRes.NormalizedLive),
})
```&lt;/p&gt;
&lt;p&gt;A user only requires RBAC to call this ServerSideDiff function. Every authenticated Argo CD user has get access via the default role:catch-all policy. However, Argo CD has a defense layer called removeWebhookMutation() that normally strips non-Argo CD-managed fields from the Server Side Apply (SSA) dry-run response and merges them with the client-provided (masked) live state. This prevents real Secret values from leaking through the diff. However, this defense is entirely skipped when the Application has the annotation argocd.argoproj.i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3v3m-wc6v-x4x3</guid>
    </item>
    <item>
      <title>RHBA-2026:12433 — Red Hat Bug Fix Advisory: Red Hat OpenShift GitOps v1.20.3 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2026:12433</link>
      <description>&lt;p&gt;argoproj/argo-cd: Argo CD: Information disclosure of Kubernetes Secret data via Server-Side Apply dry-run mechanism&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;argoproj/argo-cd: Argo CD: Information disclosure of Kubernetes Secret data via Server-Side Apply dry-run mechanism&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2026:12433</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1383 — Argo CD: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1383</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Argo CD ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Argo CD ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1383</guid>
    </item>
  </channel>
</rss>
