<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 21:21:07 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-32021 — Weblate VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintext</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-32021</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; WeblateOrg weblate&lt;/p&gt;
&lt;p&gt;Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client&amp;#39;s URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; WeblateOrg weblate&lt;/p&gt;
&lt;p&gt;Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client&amp;#39;s URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-32021</guid>
    </item>
    <item>
      <title>GHSA-m67m-3p5g-cw9j — VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintext</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m67m-3p5g-cw9j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: weblate&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client&amp;#39;s URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to the logs in plaintext.&lt;/p&gt;
&lt;p&gt;The problematic URL in question is of this form:&lt;/p&gt;
&lt;p&gt;```
https://&amp;lt;HOST&amp;gt;/create/component/vcs/?repo=https%3A%2F%2F&amp;lt;GITHUB USERNAME&amp;gt;%3A&amp;lt;GITHUB PAT&amp;gt;%40github.com%2F&amp;lt;REPOSITORY OWNER&amp;gt;%2F&amp;lt;REPOSITORY NAME&amp;gt;.git&amp;amp;project=1&amp;amp;category=&amp;amp;name=&amp;lt;REDACTED&amp;gt;&amp;amp;slug=&amp;lt;REDACTED&amp;gt;&amp;amp;is_glossary=False&amp;amp;vcs=github&amp;amp;source_language=228&amp;amp;license=&amp;amp;source_component=1#existing
```&lt;/p&gt;
&lt;p&gt;If using Weblate official Docker image, nginx logs the URL and the token in plaintext:&lt;/p&gt;
&lt;p&gt;```
nginx stdout | 127.0.0.1 - - [04/Apr/2025:10:46:54 +0000] &amp;#34;GET /create/component/vcs/?repo=https%3A%2F%2F&amp;lt;GITHUB USERNAME&amp;gt;%3A&amp;lt;GITHUB PAT&amp;gt;%40github.com%2F&amp;lt;REPOSITORY OWNER&amp;gt;%2F&amp;lt;REPOSITORY NAME&amp;gt;.git&amp;amp;project=1&amp;amp;category=&amp;amp;name=&amp;lt;REDACTED&amp;gt;&amp;amp;slug=&amp;lt;REDACTED&amp;gt;&amp;amp;is_glossary=False&amp;amp;vcs=github&amp;amp;source_language=228&amp;amp;license=&amp;amp;source_component=1 HTTP/1.1&amp;#34; 200 17625 &amp;#34;&amp;lt;REDACTED&amp;gt;&amp;#34; &amp;#34;Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### Reproduction&lt;/p&gt;
&lt;p&gt;1. In a project, create a component which has the _Repository push URL_ setting configured with, for example, a GitHub…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: weblate&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client&amp;#39;s URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to the logs in plaintext.&lt;/p&gt;
&lt;p&gt;The problematic URL in question is of this form:&lt;/p&gt;
&lt;p&gt;```
https://&amp;lt;HOST&amp;gt;/create/component/vcs/?repo=https%3A%2F%2F&amp;lt;GITHUB USERNAME&amp;gt;%3A&amp;lt;GITHUB PAT&amp;gt;%40github.com%2F&amp;lt;REPOSITORY OWNER&amp;gt;%2F&amp;lt;REPOSITORY NAME&amp;gt;.git&amp;amp;project=1&amp;amp;category=&amp;amp;name=&amp;lt;REDACTED&amp;gt;&amp;amp;slug=&amp;lt;REDACTED&amp;gt;&amp;amp;is_glossary=False&amp;amp;vcs=github&amp;amp;source_language=228&amp;amp;license=&amp;amp;source_component=1#existing
```&lt;/p&gt;
&lt;p&gt;If using Weblate official Docker image, nginx logs the URL and the token in plaintext:&lt;/p&gt;
&lt;p&gt;```
nginx stdout | 127.0.0.1 - - [04/Apr/2025:10:46:54 +0000] &amp;#34;GET /create/component/vcs/?repo=https%3A%2F%2F&amp;lt;GITHUB USERNAME&amp;gt;%3A&amp;lt;GITHUB PAT&amp;gt;%40github.com%2F&amp;lt;REPOSITORY OWNER&amp;gt;%2F&amp;lt;REPOSITORY NAME&amp;gt;.git&amp;amp;project=1&amp;amp;category=&amp;amp;name=&amp;lt;REDACTED&amp;gt;&amp;amp;slug=&amp;lt;REDACTED&amp;gt;&amp;amp;is_glossary=False&amp;amp;vcs=github&amp;amp;source_language=228&amp;amp;license=&amp;amp;source_component=1 HTTP/1.1&amp;#34; 200 17625 &amp;#34;&amp;lt;REDACTED&amp;gt;&amp;#34; &amp;#34;Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### Reproduction&lt;/p&gt;
&lt;p&gt;1. In a project, create a component which has the _Repository push URL_ setting configured with, for example, a GitHub…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m67m-3p5g-cw9j</guid>
    </item>
  </channel>
</rss>
