<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:30:23.385397+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-envoy-2026-26308</id>
    <title>BIT-envoy-2026-26308 — Envoy has an RBAC Header Validation Bypass via Multi-Value Header Concatenation</title>
    <updated>2026-10-03T19:30:23.452123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: envoy</p>
<p>Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically "Deny" rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-envoy-2026-26308"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275357</id>
    <title>EUVD-2026-275357</title>
    <updated>2026-10-03T19:30:23.452208+00:00</updated>
    <content>EUVD-2026-275357</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26308</id>
    <title>fkie_cve-2026-26308</title>
    <updated>2026-10-03T19:30:23.452239+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically "Deny" rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-26308"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ghc4-35x6-crw5</id>
    <title>GHSA-ghc4-35x6-crw5 — Envoy has RBAC Header Validation Bypass via Multi-Value Header Concatenation</title>
    <updated>2026-10-03T19:30:23.452300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/envoyproxy/envoy</p>
<p>## 1. Summary
The Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically "Deny" rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms.</p>
<p>## 2. Attack Scenario
Consider an environment where an administrator wants to block external access to internal resources using a specific header flag.</p>
<p>### Configuration
The Envoy proxy is configured with a **Deny** rule to reject requests containing the header `internal: true`.
* **Rule Type:** Exact Match
* **Target:** `internal` header must not equal `true`.</p>
<p>### The Bypass Logic
1.  **Standard Request (Blocked):**
    * **Input:** `internal: true`
    * **Envoy Processing:** Sees string `"true"`.
    * **Result:** Match found. **Request Denied.**</p>
<p>2.  **Exploit Request (Bypassed):**
    * **Input:**
        ```http
        internal: true
        internal: true
        ```
    * **Envoy Processing:** Concatenates values into `"true,true"`.
    * **Matcher Evaluation:** Does `"true,true"` equal `"true"`? **No.**
    * **Result:** The Deny rule fails to trigger. **Request Allowed.**</p>
<p>## 3. Implications
* **RBAC Bypass:** Remote attackers can bypass configured access controls.
* **Unauthoriz…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ghc4-35x6-crw5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0704</id>
    <title>WID-SEC-W-2026-0704 — Google Cloud Platform Envoy Proxy, Istio und Service Mesh: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:30:23.452386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Google Cloud Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0704"/>
  </entry>
</feed>
