<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T12:48:56.313946+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-envoy-2022-29226</id>
    <title>BIT-envoy-2022-29226 — Trivial authentication bypass in Envoy</title>
    <updated>2026-10-04T12:48:56.319755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: envoy</p>
<p>Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-envoy-2022-29226"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-543</id>
    <title>certfr-2022-avi-543 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
Red Hat. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-04T12:48:56.319806+00:00</updated>
    <content>certfr-2022-avi-543</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-543"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-82666</id>
    <title>cnvd-2022-82666</title>
    <updated>2026-10-04T12:48:56.319827+00:00</updated>
    <content>cnvd-2022-82666</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-82666"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234061</id>
    <title>EUVD-2026-234061</title>
    <updated>2026-10-04T12:48:56.319842+00:00</updated>
    <content>EUVD-2026-234061</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234061"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-29226</id>
    <title>fkie_cve-2022-29226</title>
    <updated>2026-10-04T12:48:56.319853+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-29226"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-29226</id>
    <title>gsd-2022-29226</title>
    <updated>2026-10-04T12:48:56.319876+00:00</updated>
    <content>gsd-2022-29226</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-29226"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:5004</id>
    <title>RHSA-2022:5004 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.1.3 security update</title>
    <updated>2026-10-04T12:48:56.319887+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString golang: cmd/go: misinterpretation of branch names can lead to incorrect access control golang: crypto/elliptic: IsOnCurve returns true for invalid field elements envoy: Segfault in GrpcHealthCheckerImpl envoy: Decompressors can be zip bombed envoy: oauth filter allows trivial bypass envoy: oauth filter calls continueDecoding() from within decodeHeaders() Istio: Unsafe memory access in metadata exchange.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:5004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0288</id>
    <title>WID-SEC-W-2022-0288 — Red Hat OpenShift: Mehrere Schwachstellen</title>
    <updated>2026-10-04T12:48:56.319912+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen, einen nicht näher spezifizierten Angriff durchzuführen, vertrauliche Informationen offenzulegen und Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0288"/>
  </entry>
</feed>
