<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 23:22:36 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-234123</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-234123</link>
      <description>EUVD-2026-234123</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-234123</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24905</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24905</link>
      <description>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was found in Argo CD prior to versions 2.3.4, 2.2.9, and 2.1.15 that allows an attacker to spoof error messages on the login screen when single sign on (SSO) is enabled. In order to exploit this vulnerability, an attacker would have to trick the victim to visit a specially crafted URL which contains the message to be displayed. As far as the research of the Argo CD team concluded, it is not possible to specify any active content (e.g. Javascript) or other HTML fragments (e.g. clickable links) in the spoofed message. A patch for this vulnerability has been released in Argo CD versions 2.3.4, 2.2.9, and 2.1.15. There are currently no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was found in Argo CD prior to versions 2.3.4, 2.2.9, and 2.1.15 that allows an attacker to spoof error messages on the login screen when single sign on (SSO) is enabled. In order to exploit this vulnerability, an attacker would have to trick the victim to visit a specially crafted URL which contains the message to be displayed. As far as the research of the Argo CD team concluded, it is not possible to specify any active content (e.g. Javascript) or other HTML fragments (e.g. clickable links) in the spoofed message. A patch for this vulnerability has been released in Argo CD versions 2.3.4, 2.2.9, and 2.1.15. There are currently no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24905</guid>
    </item>
    <item>
      <title>GHSA-xmg8-99r8-jc2j — Login screen allows message spoofing if SSO is enabled</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xmg8-99r8-jc2j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v2, Go: github.com/argoproj/argo-cd&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Argo CD that allows an attacker to spoof error messages on the login screen when SSO is enabled.&lt;/p&gt;
&lt;p&gt;In order to exploit this vulnerability, an attacker would have to trick the victim to visit a specially crafted URL which contains the message to be displayed.&lt;/p&gt;
&lt;p&gt;As far as the research of the Argo CD team concluded, it is not possible to specify any active content (e.g. Javascript) or other HTML fragments (e.g. clickable links) in the spoofed message.&lt;/p&gt;
&lt;p&gt;### Patched versions&lt;/p&gt;
&lt;p&gt;A patch for this vulnerability has been released in the following Argo CD versions:&lt;/p&gt;
&lt;p&gt;* v2.3.4
* v2.2.9
* v2.1.15&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;No workaround available.&lt;/p&gt;
&lt;p&gt;#### Mitigations&lt;/p&gt;
&lt;p&gt;It is advised to update to an Argo CD version containing a fix for this issue (see *Patched versions* above).&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;This vulnerability was discovered by Naufal Septiadi (&amp;lt;naufal@horangi.com&amp;gt;) and reported to us in a responsible way.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- Use only one of the paragraphs below. Remove all others. --&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- For Argo CD --&amp;gt;&lt;/p&gt;
&lt;p&gt;* Open an issue in [the Argo CD issue tracker](https://github.com/argoproj/argo-cd/issues) or [discussions](https://github.com/argoproj/argo-cd/discussions)
* Join us on [Slack](https://argoproj.github.io/community/join-slack) in channel #argo-cd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/argoproj/argo-cd/v2, Go: github.com/argoproj/argo-cd&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Argo CD that allows an attacker to spoof error messages on the login screen when SSO is enabled.&lt;/p&gt;
&lt;p&gt;In order to exploit this vulnerability, an attacker would have to trick the victim to visit a specially crafted URL which contains the message to be displayed.&lt;/p&gt;
&lt;p&gt;As far as the research of the Argo CD team concluded, it is not possible to specify any active content (e.g. Javascript) or other HTML fragments (e.g. clickable links) in the spoofed message.&lt;/p&gt;
&lt;p&gt;### Patched versions&lt;/p&gt;
&lt;p&gt;A patch for this vulnerability has been released in the following Argo CD versions:&lt;/p&gt;
&lt;p&gt;* v2.3.4
* v2.2.9
* v2.1.15&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;No workaround available.&lt;/p&gt;
&lt;p&gt;#### Mitigations&lt;/p&gt;
&lt;p&gt;It is advised to update to an Argo CD version containing a fix for this issue (see *Patched versions* above).&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;This vulnerability was discovered by Naufal Septiadi (&amp;lt;naufal@horangi.com&amp;gt;) and reported to us in a responsible way.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- Use only one of the paragraphs below. Remove all others. --&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- For Argo CD --&amp;gt;&lt;/p&gt;
&lt;p&gt;* Open an issue in [the Argo CD issue tracker](https://github.com/argoproj/argo-cd/issues) or [discussions](https://github.com/argoproj/argo-cd/discussions)
* Join us on [Slack](https://argoproj.github.io/community/join-slack) in channel #argo-cd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xmg8-99r8-jc2j</guid>
    </item>
    <item>
      <title>gsd-2022-24905</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24905</link>
      <description>gsd-2022-24905</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24905</guid>
    </item>
    <item>
      <title>RHSA-2022:4671 — Red Hat Security Advisory: Red Hat OpenShift GitOps security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:4671</link>
      <description>&lt;p&gt;argocd: Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server argocd: Login screen allows message spoofing if SSO is enabled argocd: ArgoCD will blindly trust JWT claims if anonymous access is enabled&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;argocd: Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server argocd: Login screen allows message spoofing if SSO is enabled argocd: ArgoCD will blindly trust JWT claims if anonymous access is enabled&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:4671</guid>
    </item>
  </channel>
</rss>
