<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:14:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-331650</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331650</link>
      <description>EUVD-2026-331650</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331650</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54673</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54673</link>
      <description>&lt;p&gt;electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase &amp;#34;authorization&amp;#34;, exposing credentials. Other credential-bearing headers — most notably PRIVATE-TOKEN (used by GitLab&amp;#39;s personal access token flow) and mixed-case Authorization (used by GitLab&amp;#39;s Bearer/OAuth flow) — were not stripped and could be forwarded to an attacker-controlled cross-origin redirect destination. This issue has been fixed in version 9.7.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase &amp;#34;authorization&amp;#34;, exposing credentials. Other credential-bearing headers — most notably PRIVATE-TOKEN (used by GitLab&amp;#39;s personal access token flow) and mixed-case Authorization (used by GitLab&amp;#39;s Bearer/OAuth flow) — were not stripped and could be forwarded to an attacker-controlled cross-origin redirect destination. This issue has been fixed in version 9.7.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54673</guid>
    </item>
    <item>
      <title>GHSA-p2f4-r6v6-j797 — electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-ut…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p2f4-r6v6-j797</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: builder-util-runtime&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In `electron-builder`&amp;#39;s `builder-util-runtime` package, the HTTP redirect handler (`HttpExecutor.prepareRedirectUrlOptions`) only stripped a credential header whose key string matched exactly lowercase `&amp;#34;authorization&amp;#34;`. Other credential-bearing headers — most notably `PRIVATE-TOKEN` (used by GitLab&amp;#39;s personal access token flow) and mixed-case `Authorization` (used by GitLab&amp;#39;s Bearer/OAuth flow) — were not stripped and could be forwarded to an attacker-controlled cross-origin redirect destination.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root cause&lt;/p&gt;
&lt;p&gt;`HttpExecutor.prepareRedirectUrlOptions` (introduced in `builder-util-runtime` via [PR #9211](https://github.com/electron-userland/electron-builder/pull/9211), first released in `v26.0.20`) performed its cross-origin credential strip with a single case-sensitive property check:&lt;/p&gt;
&lt;p&gt;```typescript
// vulnerable code (electron-builder v26.0.20 – v26.14.x) [via builder-util-runtime &amp;lt;9.7.0]
if (headers?.authorization) {
  if (HttpExecutor.isCrossOriginRedirect(originalUrl, parsedRedirectUrl)) {
    delete headers.authorization   // only removes the exact key &amp;#34;authorization&amp;#34;
  }
}
```&lt;/p&gt;
&lt;p&gt;JavaScript object property access is case-sensitive. The guard `headers?.authorization` evaluates to `undefined` (falsy) when the key is `&amp;#34;Authorization&amp;#34;`, `&amp;#34;AUTHORIZATION&amp;#34;`, or any other casing, so the branch is never entered and **no header is deleted** for those cases.&lt;/p&gt;
&lt;p&gt;### Affected updater flows&lt;/p&gt;
&lt;p&gt;The clearest reproduced path is the private GitLab updater flow.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: builder-util-runtime&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In `electron-builder`&amp;#39;s `builder-util-runtime` package, the HTTP redirect handler (`HttpExecutor.prepareRedirectUrlOptions`) only stripped a credential header whose key string matched exactly lowercase `&amp;#34;authorization&amp;#34;`. Other credential-bearing headers — most notably `PRIVATE-TOKEN` (used by GitLab&amp;#39;s personal access token flow) and mixed-case `Authorization` (used by GitLab&amp;#39;s Bearer/OAuth flow) — were not stripped and could be forwarded to an attacker-controlled cross-origin redirect destination.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root cause&lt;/p&gt;
&lt;p&gt;`HttpExecutor.prepareRedirectUrlOptions` (introduced in `builder-util-runtime` via [PR #9211](https://github.com/electron-userland/electron-builder/pull/9211), first released in `v26.0.20`) performed its cross-origin credential strip with a single case-sensitive property check:&lt;/p&gt;
&lt;p&gt;```typescript
// vulnerable code (electron-builder v26.0.20 – v26.14.x) [via builder-util-runtime &amp;lt;9.7.0]
if (headers?.authorization) {
  if (HttpExecutor.isCrossOriginRedirect(originalUrl, parsedRedirectUrl)) {
    delete headers.authorization   // only removes the exact key &amp;#34;authorization&amp;#34;
  }
}
```&lt;/p&gt;
&lt;p&gt;JavaScript object property access is case-sensitive. The guard `headers?.authorization` evaluates to `undefined` (falsy) when the key is `&amp;#34;Authorization&amp;#34;`, `&amp;#34;AUTHORIZATION&amp;#34;`, or any other casing, so the branch is never entered and **no header is deleted** for those cases.&lt;/p&gt;
&lt;p&gt;### Affected updater flows&lt;/p&gt;
&lt;p&gt;The clearest reproduced path is the private GitLab updater flow.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p2f4-r6v6-j797</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11200-1 — heroic-games-launcher-2.22.0-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11200-1</link>
      <description>&lt;p&gt;heroic-games-launcher-2.22.0-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;heroic-games-launcher-2.22.0-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11200-1</guid>
    </item>
  </channel>
</rss>
