<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 23:03:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-276048</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276048</link>
      <description>EUVD-2026-276048</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276048</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32598</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32598</link>
      <description>&lt;p&gt;OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user. This vulnerability is fixed in 10.0.24.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user. This vulnerability is fixed in 10.0.24.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32598</guid>
    </item>
    <item>
      <title>GHSA-4524-cj9j-g4fj — OneUptime: Password Reset Token Logged at INFO Level</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4524-cj9j-g4fj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: oneuptime&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable code — `App/FeatureSet/Identity/API/Authentication.ts` lines 370-371:**
```typescript
logger.info(&amp;#34;User forgot password: &amp;#34; + user.email?.toString());
logger.info(&amp;#34;Reset Password URL: &amp;#34; + tokenVerifyUrl);
```&lt;/p&gt;
&lt;p&gt;The `tokenVerifyUrl` is a complete URL like `https://app.oneuptime.com/accounts/reset-password/&amp;lt;plaintext-token&amp;gt;`. This is logged at INFO level, which is enabled by default in production and persisted to stdout, log files, and any configured log aggregation systems.&lt;/p&gt;
&lt;p&gt;**Additionally — login credentials logged at DEBUG level (line 909):**
```typescript
logger.debug(&amp;#34;Login request data: &amp;#34; + JSON.stringify(req.body, null, 2));
```&lt;/p&gt;
&lt;p&gt;The entire login request body (including cleartext password) is logged at DEBUG level. While DEBUG is typically disabled in production, it is commonly enabled during incident troubleshooting.&lt;/p&gt;
&lt;p&gt;No existing CVEs cover sensitive data exposure in logging for OneUptime. CVE-2026-30956 (GHSA-r5v6-2599-9g3m) leaked `resetPasswordToken` from the database via multi-tenant header bypass — this finding is different (token leaked via application logs).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;**Environment:** OneUptime v10.0.23 via…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: oneuptime&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable code — `App/FeatureSet/Identity/API/Authentication.ts` lines 370-371:**
```typescript
logger.info(&amp;#34;User forgot password: &amp;#34; + user.email?.toString());
logger.info(&amp;#34;Reset Password URL: &amp;#34; + tokenVerifyUrl);
```&lt;/p&gt;
&lt;p&gt;The `tokenVerifyUrl` is a complete URL like `https://app.oneuptime.com/accounts/reset-password/&amp;lt;plaintext-token&amp;gt;`. This is logged at INFO level, which is enabled by default in production and persisted to stdout, log files, and any configured log aggregation systems.&lt;/p&gt;
&lt;p&gt;**Additionally — login credentials logged at DEBUG level (line 909):**
```typescript
logger.debug(&amp;#34;Login request data: &amp;#34; + JSON.stringify(req.body, null, 2));
```&lt;/p&gt;
&lt;p&gt;The entire login request body (including cleartext password) is logged at DEBUG level. While DEBUG is typically disabled in production, it is commonly enabled during incident troubleshooting.&lt;/p&gt;
&lt;p&gt;No existing CVEs cover sensitive data exposure in logging for OneUptime. CVE-2026-30956 (GHSA-r5v6-2599-9g3m) leaked `resetPasswordToken` from the database via multi-tenant header bypass — this finding is different (token leaked via application logs).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;**Environment:** OneUptime v10.0.23 via…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4524-cj9j-g4fj</guid>
    </item>
  </channel>
</rss>
