CVE-2025-13353: Cloudflare gokey — Broken Cryptographic Design Allows Master Password Bypass Severity: High (8.1) | Published: December 2, 2025 A cryptographic design bug in Cloudflare's gokey vaultless password manager caused the AES-GCM decrypted seed bytes to be discarded during the unwrap step. The resulting derivation inputs (nonce, zeros, tag) were all publicly available inside the encrypted seed file, allowing an attacker with only the seed file to regenerate all derived secrets without the master password. Advisory: GHSA-69jw-4jj8-fcxm
CVE-2025-41118: Exposure of Storage Secret in Grafana Pyroscope Severity: Critical (CVSS 9.1) | Published: January 2, 2026 Grafana Pyroscope's COS (Tencent Cloud Object Storage) provider config stored the secret_key as a plain string instead of using the flagext.Secret masked type. This caused the live secret_key to be returned in plaintext via the /api/v1/status/config endpoint, enabling credential theft by anyone with access to the status API. Advisory: CVE-2025-41118