<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:43:29.377054+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-envoy-2026-73546</id>
    <title>BIT-envoy-2026-73546 — Envoy: Stored XSS in Admin Stats Interface (/stats?format=html)</title>
    <updated>2026-10-02T10:43:29.389800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: envoy</p>
<p>Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component such as grpc_stats with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface's origin and issue privileged same-origin requests. The relevant scope boundary is that the admin interface must be browser-accessible and an enabled component must persist attacker-influenced text in statistic names. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-envoy-2026-73546"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-373256</id>
    <title>EUVD-2026-373256</title>
    <updated>2026-10-02T10:43:29.389860+00:00</updated>
    <content>EUVD-2026-373256</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-373256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73546</id>
    <title>fkie_cve-2026-73546</title>
    <updated>2026-10-02T10:43:29.389876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component such as grpc_stats with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface's origin and issue privileged same-origin requests. The relevant scope boundary is that the admin interface must be browser-accessible and an enabled component must persist attacker-influenced text in statistic names. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73546"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11630-1</id>
    <title>openSUSE-SU-2026:11630-1 — istioctl-1.30.4-1.1 on GA media</title>
    <updated>2026-10-02T10:43:29.389904+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>istioctl-1.30.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11630-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:65106</id>
    <title>RHSA-2026:65106 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.0.15</title>
    <updated>2026-10-02T10:43:29.389934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls envoy: envoy: ext_authz use-after-free after rejecting an HTTP request net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages envoy: envoy: path matching bypass via per-segment parameters not stripped by router envoy: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free envoy: envoy: stored XSS through dynamically generated stat names in admin interface envoy: envoy: ext_authz crash on CONNECT requests without :path pseudo-header envoy: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests envoy: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters envoy: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits envoy: envoy: path normalization bypass via dot/dot-dot segments with parameters envoy: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values e…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:65106"/>
  </entry>
</feed>
