<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T10:04:36.947256+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-02074</id>
    <title>bdu:2019-02074</title>
    <updated>2026-10-09T10:04:36.950918+00:00</updated>
    <content>bdu:2019-02074</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-02074"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-53204</id>
    <title>EUVD-2026-53204</title>
    <updated>2026-10-09T10:04:36.950950+00:00</updated>
    <content>EUVD-2026-53204</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-53204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-9900</id>
    <title>fkie_cve-2019-9900</title>
    <updated>2026-10-09T10:04:36.950964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-9900"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h9r7-c397-3wqr</id>
    <title>GHSA-h9r7-c397-3wqr</title>
    <updated>2026-10-09T10:04:36.950992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h9r7-c397-3wqr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-9900</id>
    <title>gsd-2019-9900</title>
    <updated>2026-10-09T10:04:36.951008+00:00</updated>
    <content>gsd-2019-9900</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-9900"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:0741</id>
    <title>RHSA-2019:0741 — Red Hat Security Advisory: Istio-Proxy Security Update</title>
    <updated>2026-10-09T10:04:36.951019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>istio/envoy: Authorization bypass via null characters injection in HTTP/1.x istio/envoy: Path traversal via URL Patch manipulation in HTTP/1.x header</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:0741"/>
  </entry>
</feed>
