<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:28:24.760173+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-envoy-2026-48042</id>
    <title>BIT-envoy-2026-48042 — Envoy: Stack overflow in destructor of highly nested JSON</title>
    <updated>2026-10-02T14:28:24.786473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: envoy</p>
<p>Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-envoy-2026-48042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331015</id>
    <title>EUVD-2026-331015</title>
    <updated>2026-10-02T14:28:24.786538+00:00</updated>
    <content>EUVD-2026-331015</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331015"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48042</id>
    <title>fkie_cve-2026-48042</title>
    <updated>2026-10-02T14:28:24.786556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11141-1</id>
    <title>openSUSE-SU-2026:11141-1 — istioctl-1.30.2-1.1 on GA media</title>
    <updated>2026-10-02T14:28:24.786579+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>istioctl-1.30.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11141-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:49705</id>
    <title>RHSA-2026:49705 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.0.14</title>
    <updated>2026-10-02T14:28:24.786599+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries envoy: Envoy: Denial of Service via Connect protocol request envoy: Envoy: Null pointer deref in internal redirects envoy: Envoy: Denial of Service via deeply nested JSON objects Envoy: Envoy: Denial of Service via specially crafted zstd payload</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:49705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2048</id>
    <title>WID-SEC-W-2026-2048 — Google Cloud Service Mesh und Envoy Proxy: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:28:24.786620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Google Cloud Service Mesh und Envoy Proxy ausnutzen, um einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere, nicht näher bezeichnete Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2048"/>
  </entry>
</feed>
