<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 04:34:56 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-336096</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336096</link>
      <description>EUVD-2026-336096</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336096</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59155</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59155</link>
      <description>&lt;p&gt;Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&amp;amp;M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API credentials, including Cloudflare API tokens, TencentCloud SecretKeys, Slack, Discord, and Telegram webhook URLs with embedded bot tokens, and Authorization header values, without any field-level redaction. Any authenticated admin or PAT with nezha:ddns:read or nezha:notification:read scope can receive stored credentials through the listDDNS and listNotification handlers in a single API response. This issue is fixed in version 2.2.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&amp;amp;M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API credentials, including Cloudflare API tokens, TencentCloud SecretKeys, Slack, Discord, and Telegram webhook URLs with embedded bot tokens, and Authorization header values, without any field-level redaction. Any authenticated admin or PAT with nezha:ddns:read or nezha:notification:read scope can receive stored credentials through the listDDNS and listNotification handlers in a single API response. This issue is fixed in version 2.2.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59155</guid>
    </item>
    <item>
      <title>GHSA-ww5p-j6cj-6mqq — Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ww5p-j6cj-6mqq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/nezhahq/nezha&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `GET /api/v1/ddns` and `GET /api/v1/notification` endpoints return full resource objects including plaintext third-party API credentials — Cloudflare API tokens, TencentCloud SecretKeys, Slack/Discord/Telegram webhook URLs with embedded bot tokens, and Authorization header values — without any field-level redaction. Any authenticated admin who calls these endpoints receives every stored credential in the system in a single API response. A compromised admin session or leaked PAT with `nezha:ddns:read` or `nezha:notification:read` scope exposes all third-party integration secrets.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `listDDNS` and `listNotification` handlers follow an identical pattern: they call the corresponding singleton `GetSortedList()`, `copier.Copy` the full in-memory structs into a response slice, and return them via `listHandler` with zero field stripping.&lt;/p&gt;
&lt;p&gt;**DDNS — `cmd/dashboard/controller/ddns.go:25–33`:**&lt;/p&gt;
&lt;p&gt;```go
func listDDNS(c *gin.Context) ([]*model.DDNSProfile, error) {
    var ddnsProfiles []*model.DDNSProfile
    list := singleton.DDNSShared.GetSortedList()
    if err := copier.Copy(&amp;amp;ddnsProfiles, &amp;amp;list); err != nil {
        return nil, err
    }
    return ddnsProfiles, nil
}
```&lt;/p&gt;
&lt;p&gt;The `DDNSProfile` struct (`model/ddns.go:20–36`) serializes `AccessSecret` with `json:&amp;#34;access_secret,omitempty&amp;#34;` — non-empty Cloudflare tokens and TencentCloud SecretKeys are returned in cleartext. The `WebhookURL` and `WebhookHeaders` fields may also contain embedded secrets.&lt;/p&gt;
&lt;p&gt;**N…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/nezhahq/nezha&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `GET /api/v1/ddns` and `GET /api/v1/notification` endpoints return full resource objects including plaintext third-party API credentials — Cloudflare API tokens, TencentCloud SecretKeys, Slack/Discord/Telegram webhook URLs with embedded bot tokens, and Authorization header values — without any field-level redaction. Any authenticated admin who calls these endpoints receives every stored credential in the system in a single API response. A compromised admin session or leaked PAT with `nezha:ddns:read` or `nezha:notification:read` scope exposes all third-party integration secrets.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `listDDNS` and `listNotification` handlers follow an identical pattern: they call the corresponding singleton `GetSortedList()`, `copier.Copy` the full in-memory structs into a response slice, and return them via `listHandler` with zero field stripping.&lt;/p&gt;
&lt;p&gt;**DDNS — `cmd/dashboard/controller/ddns.go:25–33`:**&lt;/p&gt;
&lt;p&gt;```go
func listDDNS(c *gin.Context) ([]*model.DDNSProfile, error) {
    var ddnsProfiles []*model.DDNSProfile
    list := singleton.DDNSShared.GetSortedList()
    if err := copier.Copy(&amp;amp;ddnsProfiles, &amp;amp;list); err != nil {
        return nil, err
    }
    return ddnsProfiles, nil
}
```&lt;/p&gt;
&lt;p&gt;The `DDNSProfile` struct (`model/ddns.go:20–36`) serializes `AccessSecret` with `json:&amp;#34;access_secret,omitempty&amp;#34;` — non-empty Cloudflare tokens and TencentCloud SecretKeys are returned in cleartext. The `WebhookURL` and `WebhookHeaders` fields may also contain embedded secrets.&lt;/p&gt;
&lt;p&gt;**N…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ww5p-j6cj-6mqq</guid>
    </item>
  </channel>
</rss>
