<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:59:44.100771+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01040</id>
    <title>bdu:2026-01040</title>
    <updated>2026-10-03T12:59:44.107366+00:00</updated>
    <content>bdu:2026-01040</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-my21105</id>
    <title>CLEANSTART-2026-MY21105 — Security fix for CVE-2026-22771 applied in: tigera-operator 1.39.3-r1, tigera-operator-fips 1.37.2-r4</title>
    <updated>2026-10-03T12:59:44.107399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: tigera-operator, CleanStart: tigera-operator-fips</p>
<p>CVE-2026-22771 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-my21105"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337496</id>
    <title>EUVD-2026-337496</title>
    <updated>2026-10-03T12:59:44.107431+00:00</updated>
    <content>EUVD-2026-337496</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22771</id>
    <title>fkie_cve-2026-22771</title>
    <updated>2026-10-03T12:59:44.107444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22771"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xrwg-mqj6-6m22</id>
    <title>GHSA-xrwg-mqj6-6m22 — Envoy Extension Policy lua scripts injection causes arbitrary command execution</title>
    <updated>2026-10-03T12:59:44.107469+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/envoyproxy/gateway</p>
<p>### Impact
Envoy Gateway allows users to create Lua scripts that are executed by Envoy proxy using the `EnvoyExtensionPolicy` resource. Administrators can use Kubernetes RBAC to grant users the ability to create `EnvoyExtensionPolicy` resources. Lua scripts in policies are executed in two contexts:
* An `EnvoyExtensionPolicy` can be attached to Gateway and xRoute resources. Lua scripts in the policy will process traffic in that scope.
* Lua scripts are interpreted and run by the Envoy Gateway controller pod for validation purposes.</p>
<p>Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication.</p>
<p>For example, the following EnvoyExtensionPolicy, when executed by Envoy proxy, will leak the proxy's XDS client certificates.</p>
<p>```yaml
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyExtensionPolicy
metadata:
  name: lua-leak
spec:
  targetRefs:
    - group: gateway.networking.k8s.io
      kind: HTTPRoute
      name: leak
  lua:
    - type: Inline
      inline: |
           function envoy_on_response(response_handle)
             local cert = io.open("/certs/tls.crt", "r")
             local content
             if cert then
                content = cert:read("*all")
                cert:close()
             else
                content =…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xrwg-mqj6-6m22"/>
  </entry>
</feed>
