<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 11:11:37 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-10005 — Consul L7 Intentions Vulnerable To URL Path Bypass</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-10005</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; HashiCorp Consul, HashiCorp Consul Enterprise&lt;/p&gt;
&lt;p&gt;A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; HashiCorp Consul, HashiCorp Consul Enterprise&lt;/p&gt;
&lt;p&gt;A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-10005</guid>
    </item>
    <item>
      <title>GHSA-2464-8j7c-4cjm — go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2464-8j7c-4cjm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-viper/mapstructure/v2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Use of this library in a security-critical context may result in leaking sensitive information, if used to process sensitive fields.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;OpenBao (and presumably HashiCorp Vault) have surfaced error messages from `mapstructure` as follows:&lt;/p&gt;
&lt;p&gt;https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L43-L50&lt;/p&gt;
&lt;p&gt;```go
			_, _, err := d.getPrimitive(field, schema)
			if err != nil {
				return fmt.Errorf(&amp;#34;error converting input for field %q: %w&amp;#34;, field, err)
			}
```&lt;/p&gt;
&lt;p&gt;where this calls `mapstructure.WeakDecode(...)`: https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L181-L193&lt;/p&gt;
&lt;p&gt;```go&lt;/p&gt;
&lt;p&gt;func (d *FieldData) getPrimitive(k string, schema *FieldSchema) (interface{}, bool, error) {
	raw, ok := d.Raw[k]
	if !ok {
		return nil, false, nil
	}&lt;/p&gt;
&lt;p&gt;switch t := schema.Type; t {
	case TypeBool:
		var result bool
		if err := mapstructure.WeakDecode(raw, &amp;amp;result); err != nil {
			return nil, false, err
		}
		return result, true, nil
```&lt;/p&gt;
&lt;p&gt;Notably, `WeakDecode(...)` eventually calls one of the decode helpers, which surfaces the original value via `strconv` helpers:&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L720-L727&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L791-L798&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-viper/mapstructure/v2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Use of this library in a security-critical context may result in leaking sensitive information, if used to process sensitive fields.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;OpenBao (and presumably HashiCorp Vault) have surfaced error messages from `mapstructure` as follows:&lt;/p&gt;
&lt;p&gt;https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L43-L50&lt;/p&gt;
&lt;p&gt;```go
			_, _, err := d.getPrimitive(field, schema)
			if err != nil {
				return fmt.Errorf(&amp;#34;error converting input for field %q: %w&amp;#34;, field, err)
			}
```&lt;/p&gt;
&lt;p&gt;where this calls `mapstructure.WeakDecode(...)`: https://github.com/openbao/openbao/blob/98c3a59c040efca724353ca46ca79bd5cdbab920/sdk/framework/field_data.go#L181-L193&lt;/p&gt;
&lt;p&gt;```go&lt;/p&gt;
&lt;p&gt;func (d *FieldData) getPrimitive(k string, schema *FieldSchema) (interface{}, bool, error) {
	raw, ok := d.Raw[k]
	if !ok {
		return nil, false, nil
	}&lt;/p&gt;
&lt;p&gt;switch t := schema.Type; t {
	case TypeBool:
		var result bool
		if err := mapstructure.WeakDecode(raw, &amp;amp;result); err != nil {
			return nil, false, err
		}
		return result, true, nil
```&lt;/p&gt;
&lt;p&gt;Notably, `WeakDecode(...)` eventually calls one of the decode helpers, which surfaces the original value via `strconv` helpers:&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L720-L727&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a38/mapstructure.go#L791-L798&lt;/p&gt;
&lt;p&gt;https://github.com/go-viper/mapstructure/blob/8c61ec1924fcfa522f9fc6b4618c672db61d1a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2464-8j7c-4cjm</guid>
    </item>
  </channel>
</rss>
