<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 02:13:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-371970</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371970</link>
      <description>EUVD-2026-371970</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371970</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63406</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63406</link>
      <description>&lt;p&gt;AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in telemetry/telemetry.go reads the full configuration file and raw os.Args returned by anycableCLIArgs, including values supplied through --secret, --jwt_secret, and --http_rpc_secret. These inputs are passed to generateDigest, where sha256.New produces the hexadecimal fingerprint that is sent as telemetry. The available source therefore does not show raw credentials leaving the process or establish the advisory&amp;#39;s claimed confidentiality loss, although the stable fingerprint is derived from secret-bearing configuration and the default telemetry client uses publicly known authentication material. This issue is fixed in version 1.6.15.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in telemetry/telemetry.go reads the full configuration file and raw os.Args returned by anycableCLIArgs, including values supplied through --secret, --jwt_secret, and --http_rpc_secret. These inputs are passed to generateDigest, where sha256.New produces the hexadecimal fingerprint that is sent as telemetry. The available source therefore does not show raw credentials leaving the process or establish the advisory&amp;#39;s claimed confidentiality loss, although the stable fingerprint is derived from secret-bearing configuration and the default telemetry client uses publicly known authentication material. This issue is fixed in version 1.6.15.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63406</guid>
    </item>
    <item>
      <title>GHSA-w72w-9qmj-c9qm — AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w72w-9qmj-c9qm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/anycable/anycable&lt;/p&gt;
&lt;p&gt;### Summary
The telemetry subsystem embeds a hardcoded auth token (`&amp;#34;secret&amp;#34;`) in the public source and transmits raw CLI arguments—including `--secret`, `--jwt_secret`, and `--http_rpc_secret` values—to a third-party telemetry endpoint.&lt;/p&gt;
&lt;p&gt;### Details
In `telemetry/config.go` line 12, `var authToken = &amp;#34;secret&amp;#34;` is committed in the public repository and used to authenticate to `https://telemetry.anycable.io`. In `telemetry/telemetry.go`, `clusterFingerprint()` (line 320) calls both `anycableFileConfig(c.ConfigFilePath)` (line 333), which reads the full TOML config file contents, and `anycableCLIArgs()` (line 402), which reads `os.Args[1:]` verbatim—including any `--secret=...`, `--jwt_secret=...`, `--http_rpc_secret=...` arguments. Both raw values are passed to `generateDigest()` (line 373), meaning the actual secret strings flow through the code path and are included in telemetry data sent to the third-party server. Since the hardcoded `authToken = &amp;#34;secret&amp;#34;` is public, any attacker who can perform DNS hijacking or is positioned on the network path can intercept and read the telemetry payload containing operator credentials.&lt;/p&gt;
&lt;p&gt;### PoC
1. Read `telemetry/config.go` in the public repo to find `authToken = &amp;#34;secret&amp;#34;`.
2. Set up a DNS spoof for `telemetry.anycable.io` pointing to an attacker-controlled server.
3. Start anycable-go with `--secret=my-production-secret`.
4. The server sends a POST to the attacker&amp;#39;s endpoint with the telemetry JSON payload. The `clusterFingerprint` fiel…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/anycable/anycable&lt;/p&gt;
&lt;p&gt;### Summary
The telemetry subsystem embeds a hardcoded auth token (`&amp;#34;secret&amp;#34;`) in the public source and transmits raw CLI arguments—including `--secret`, `--jwt_secret`, and `--http_rpc_secret` values—to a third-party telemetry endpoint.&lt;/p&gt;
&lt;p&gt;### Details
In `telemetry/config.go` line 12, `var authToken = &amp;#34;secret&amp;#34;` is committed in the public repository and used to authenticate to `https://telemetry.anycable.io`. In `telemetry/telemetry.go`, `clusterFingerprint()` (line 320) calls both `anycableFileConfig(c.ConfigFilePath)` (line 333), which reads the full TOML config file contents, and `anycableCLIArgs()` (line 402), which reads `os.Args[1:]` verbatim—including any `--secret=...`, `--jwt_secret=...`, `--http_rpc_secret=...` arguments. Both raw values are passed to `generateDigest()` (line 373), meaning the actual secret strings flow through the code path and are included in telemetry data sent to the third-party server. Since the hardcoded `authToken = &amp;#34;secret&amp;#34;` is public, any attacker who can perform DNS hijacking or is positioned on the network path can intercept and read the telemetry payload containing operator credentials.&lt;/p&gt;
&lt;p&gt;### PoC
1. Read `telemetry/config.go` in the public repo to find `authToken = &amp;#34;secret&amp;#34;`.
2. Set up a DNS spoof for `telemetry.anycable.io` pointing to an attacker-controlled server.
3. Start anycable-go with `--secret=my-production-secret`.
4. The server sends a POST to the attacker&amp;#39;s endpoint with the telemetry JSON payload. The `clusterFingerprint` fiel…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w72w-9qmj-c9qm</guid>
    </item>
  </channel>
</rss>
