<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 08:09:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-242477</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-242477</link>
      <description>EUVD-2026-242477</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-242477</guid>
    </item>
    <item>
      <title>fkie_cve-2025-48955</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48955</link>
      <description>&lt;p&gt;Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret keys in logs without redaction. These credentials are later reused in variable assignments for persistence but do not require logging for debugging or system health purposes. Version 1.50.8 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret keys in logs without redaction. These credentials are later reused in variable assignments for persistence but do not require logging for debugging or system health purposes. Version 1.50.8 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-48955</guid>
    </item>
    <item>
      <title>GHSA-v75g-77vf-6jjq — Para Server Logs Sensitive Information</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v75g-77vf-6jjq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.erudika:para-server&lt;/p&gt;
&lt;p&gt;CWE ID: CWE-532 (Insertion of Sensitive Information into Log File)
CVSS:  7.5 (High)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&lt;/p&gt;
&lt;p&gt;**Affected Component:** Para Server Initialization Logging
**Version:** Para v1.50.6
**File Path:** `para-1.50.6/para-server/src/main/java/com/erudika/para/server/utils/HealthUtils.java`
**Vulnerable Line(s):** Line 132 (via `logger.info(...)` with root credentials)&lt;/p&gt;
&lt;p&gt;Technical Details:&lt;/p&gt;
&lt;p&gt;The vulnerability is located in the HealthUtils.java file, where a failed configuration file write triggers the following logging statement:
```java
logger.info(&amp;#34;Initialized root app with access key &amp;#39;{}&amp;#39; and secret &amp;#39;{}&amp;#39;, but could not write these to {}.&amp;#34;,
    rootAppCredentials.get(&amp;#34;accessKey&amp;#34;),
    rootAppCredentials.get(&amp;#34;secretKey&amp;#34;),
    confFile);
```
This exposes both access and secret keys in logs without redaction. These credentials are later reused in variable assignments for persistence but do not require logging for debugging or system health purposes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.erudika:para-server&lt;/p&gt;
&lt;p&gt;CWE ID: CWE-532 (Insertion of Sensitive Information into Log File)
CVSS:  7.5 (High)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&lt;/p&gt;
&lt;p&gt;**Affected Component:** Para Server Initialization Logging
**Version:** Para v1.50.6
**File Path:** `para-1.50.6/para-server/src/main/java/com/erudika/para/server/utils/HealthUtils.java`
**Vulnerable Line(s):** Line 132 (via `logger.info(...)` with root credentials)&lt;/p&gt;
&lt;p&gt;Technical Details:&lt;/p&gt;
&lt;p&gt;The vulnerability is located in the HealthUtils.java file, where a failed configuration file write triggers the following logging statement:
```java
logger.info(&amp;#34;Initialized root app with access key &amp;#39;{}&amp;#39; and secret &amp;#39;{}&amp;#39;, but could not write these to {}.&amp;#34;,
    rootAppCredentials.get(&amp;#34;accessKey&amp;#34;),
    rootAppCredentials.get(&amp;#34;secretKey&amp;#34;),
    confFile);
```
This exposes both access and secret keys in logs without redaction. These credentials are later reused in variable assignments for persistence but do not require logging for debugging or system health purposes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v75g-77vf-6jjq</guid>
    </item>
  </channel>
</rss>
