<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 22:22:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-42690</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42690</link>
      <description>EUVD-2026-42690</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42690</guid>
    </item>
    <item>
      <title>fkie_cve-2020-15125</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15125</link>
      <description>&lt;p&gt;In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0&amp;#39;s management API&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0&amp;#39;s management API&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-15125</guid>
    </item>
    <item>
      <title>GHSA-5jpf-pj32-xx53 — Authorization header is not sanitized in an error object in auth0</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5jpf-pj32-xx53</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: auth0&lt;/p&gt;
&lt;p&gt;### Overview
Versions before and including `2.27.0` use a block list of specific keys that should be sanitized from the request object contained in the error object.  When a request to Auth0 management API fails, the key for `Authorization` header is not sanitized and the `Authorization` header value can be logged exposing a bearer token.&lt;/p&gt;
&lt;p&gt;### Am I affected?
You are affected by this vulnerability if all of the following conditions apply:&lt;/p&gt;
&lt;p&gt;- You are using `auth0` npm package
- You are using a Machine to Machine application authorized to use Auth0&amp;#39;s management API https://auth0.com/docs/flows/concepts/client-credentials&lt;/p&gt;
&lt;p&gt;### How to fix that?
Upgrade to version `2.27.1`&lt;/p&gt;
&lt;p&gt;### Will this update impact my users?
The fix provided in patch will not affect your users.&lt;/p&gt;
&lt;p&gt;### Credit
http://github.com/osdiab&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: auth0&lt;/p&gt;
&lt;p&gt;### Overview
Versions before and including `2.27.0` use a block list of specific keys that should be sanitized from the request object contained in the error object.  When a request to Auth0 management API fails, the key for `Authorization` header is not sanitized and the `Authorization` header value can be logged exposing a bearer token.&lt;/p&gt;
&lt;p&gt;### Am I affected?
You are affected by this vulnerability if all of the following conditions apply:&lt;/p&gt;
&lt;p&gt;- You are using `auth0` npm package
- You are using a Machine to Machine application authorized to use Auth0&amp;#39;s management API https://auth0.com/docs/flows/concepts/client-credentials&lt;/p&gt;
&lt;p&gt;### How to fix that?
Upgrade to version `2.27.1`&lt;/p&gt;
&lt;p&gt;### Will this update impact my users?
The fix provided in patch will not affect your users.&lt;/p&gt;
&lt;p&gt;### Credit
http://github.com/osdiab&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5jpf-pj32-xx53</guid>
    </item>
    <item>
      <title>gsd-2020-15125</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-15125</link>
      <description>gsd-2020-15125</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-15125</guid>
    </item>
  </channel>
</rss>
