<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:45:13 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-61729 — Excessive resource consumption when printing error string for host certificate validation in crypto/x509</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-61729</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go standard library crypto/x509&lt;/p&gt;
&lt;p&gt;Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go standard library crypto/x509&lt;/p&gt;
&lt;p&gt;Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-61729</guid>
    </item>
    <item>
      <title>GHSA-2464-8j7c-4cjm — go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2464-8j7c-4cjm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-viper/mapstructure/v2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Use of this library in a security-critical context may result in leaking sensitive information, if used to process sensitive fields.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;OpenBao (and presumably HashiCorp Vault) have surfaced error messages from `mapstructure` as follows:&lt;/p&gt;
&lt;p&gt;https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L43-L50&lt;/p&gt;
&lt;p&gt;```go
			_, _, err := d.getPrimitive(field, schema)
			if err != nil {
				return fmt.Errorf(&amp;#34;error converting input for field %q: %w&amp;#34;, field, err)
			}
```&lt;/p&gt;
&lt;p&gt;where this calls `mapstructure.WeakDecode(...)`: https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L181-L193&lt;/p&gt;
&lt;p&gt;```go&lt;/p&gt;
&lt;p&gt;func (d *FieldData) getPrimitive(k string, schema *FieldSchema) (interface{}, bool, error) {
	raw, ok := d.Raw[k]
	if !ok {
		return nil, false, nil
	}&lt;/p&gt;
&lt;p&gt;switch t := schema.Type; t {
	case TypeBool:
		var result bool
		if err := mapstructure.WeakDecode(raw, &amp;amp;result); err != nil {
			return nil, false, err
		}
		return result, true, nil
```&lt;/p&gt;
&lt;p&gt;Notably, `WeakDecode(...)` eventually calls one of the decode helpers, which surfaces the original value via `strconv` helpers:&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L720-L727&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L791-L798&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-viper/mapstructure/v2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Use of this library in a security-critical context may result in leaking sensitive information, if used to process sensitive fields.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;OpenBao (and presumably HashiCorp Vault) have surfaced error messages from `mapstructure` as follows:&lt;/p&gt;
&lt;p&gt;https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L43-L50&lt;/p&gt;
&lt;p&gt;```go
			_, _, err := d.getPrimitive(field, schema)
			if err != nil {
				return fmt.Errorf(&amp;#34;error converting input for field %q: %w&amp;#34;, field, err)
			}
```&lt;/p&gt;
&lt;p&gt;where this calls `mapstructure.WeakDecode(...)`: https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L181-L193&lt;/p&gt;
&lt;p&gt;```go&lt;/p&gt;
&lt;p&gt;func (d *FieldData) getPrimitive(k string, schema *FieldSchema) (interface{}, bool, error) {
	raw, ok := d.Raw[k]
	if !ok {
		return nil, false, nil
	}&lt;/p&gt;
&lt;p&gt;switch t := schema.Type; t {
	case TypeBool:
		var result bool
		if err := mapstructure.WeakDecode(raw, &amp;amp;result); err != nil {
			return nil, false, err
		}
		return result, true, nil
```&lt;/p&gt;
&lt;p&gt;Notably, `WeakDecode(...)` eventually calls one of the decode helpers, which surfaces the original value via `strconv` helpers:&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L720-L727&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L791-L798&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2464-8j7c-4cjm</guid>
    </item>
  </channel>
</rss>
