<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:53:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-328964</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328964</link>
      <description>EUVD-2026-328964</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328964</guid>
    </item>
    <item>
      <title>fkie_cve-2026-11746</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-11746</link>
      <description>&lt;p&gt;A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-11746</guid>
    </item>
    <item>
      <title>GHSA-2j95-gqxf-v3vg — Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2j95-gqxf-v3vg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.linecorp.centraldogma:centraldogma-server&lt;/p&gt;
&lt;p&gt;## Vulnerability&lt;/p&gt;
&lt;p&gt;`ZooKeeperReplicationConfig.secret()` silently substitutes the hard-coded constant `&amp;#34;ch4n63m3&amp;#34;` (leetspeak for &amp;#34;change me&amp;#34;) whenever the operator omits `replication.secret`. The same secret is wired into both the **client-facing SASL context** and the **quorum/learner SASL contexts** of the embedded ZooKeeper. The constant is in OSS source on GitHub and is discoverable via code search in seconds.&lt;/p&gt;
&lt;p&gt;### Three Reinforcing Defects&lt;/p&gt;
&lt;p&gt;1. **OSS-public credential** — `DEFAULT_SECRET` is in `line/centraldogma` source.
2. **Silent fallback** — `firstNonNull(convertValue(...), DEFAULT_SECRET)` substitutes the default with no log, no warning, no startup banner. The only sanity check `checkArgument(!secret().isEmpty(), ...)` passes because the getter substitutes the literal before the emptiness check runs.
3. **Dual-purpose secret** — used for both ZK client-port super auth and inter-peer quorum SASL. A single leaked password authenticates against both surfaces.&lt;/p&gt;
&lt;p&gt;### Architecture Context (Important)&lt;/p&gt;
&lt;p&gt;Central Dogma does **NOT** connect to an external ZooKeeper ensemble. Each replica embeds a `QuorumPeer` (`EmbeddedZooKeeper extends QuorumPeer`) inside its own JVM. The Central Dogma cluster **IS** the ZK ensemble. So the &amp;#34;ZK network&amp;#34; is the inter-replica network of the Central Dogma cluster itself.&lt;/p&gt;
&lt;p&gt;### Applicability&lt;/p&gt;
&lt;p&gt;| `replication.method` | ZK Started? | Applicable? |
|---|---|---|
| `NONE` (standalone, dev default) | No | **NOT applicable** |
| `ZOOKEEPER` (HA productio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.linecorp.centraldogma:centraldogma-server&lt;/p&gt;
&lt;p&gt;## Vulnerability&lt;/p&gt;
&lt;p&gt;`ZooKeeperReplicationConfig.secret()` silently substitutes the hard-coded constant `&amp;#34;ch4n63m3&amp;#34;` (leetspeak for &amp;#34;change me&amp;#34;) whenever the operator omits `replication.secret`. The same secret is wired into both the **client-facing SASL context** and the **quorum/learner SASL contexts** of the embedded ZooKeeper. The constant is in OSS source on GitHub and is discoverable via code search in seconds.&lt;/p&gt;
&lt;p&gt;### Three Reinforcing Defects&lt;/p&gt;
&lt;p&gt;1. **OSS-public credential** — `DEFAULT_SECRET` is in `line/centraldogma` source.
2. **Silent fallback** — `firstNonNull(convertValue(...), DEFAULT_SECRET)` substitutes the default with no log, no warning, no startup banner. The only sanity check `checkArgument(!secret().isEmpty(), ...)` passes because the getter substitutes the literal before the emptiness check runs.
3. **Dual-purpose secret** — used for both ZK client-port super auth and inter-peer quorum SASL. A single leaked password authenticates against both surfaces.&lt;/p&gt;
&lt;p&gt;### Architecture Context (Important)&lt;/p&gt;
&lt;p&gt;Central Dogma does **NOT** connect to an external ZooKeeper ensemble. Each replica embeds a `QuorumPeer` (`EmbeddedZooKeeper extends QuorumPeer`) inside its own JVM. The Central Dogma cluster **IS** the ZK ensemble. So the &amp;#34;ZK network&amp;#34; is the inter-replica network of the Central Dogma cluster itself.&lt;/p&gt;
&lt;p&gt;### Applicability&lt;/p&gt;
&lt;p&gt;| `replication.method` | ZK Started? | Applicable? |
|---|---|---|
| `NONE` (standalone, dev default) | No | **NOT applicable** |
| `ZOOKEEPER` (HA productio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2j95-gqxf-v3vg</guid>
    </item>
  </channel>
</rss>
