<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:48:53 +0000</lastBuildDate>
    <item>
      <title>BIT-envoy-2022-29226 — Trivial authentication bypass in Envoy</title>
      <link>https://cve.radiocsirt.org/vuln/bit-envoy-2022-29226</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-envoy-2022-29226</guid>
    </item>
    <item>
      <title>certfr-2022-avi-543 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-543</link>
      <description>certfr-2022-avi-543</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-543</guid>
    </item>
    <item>
      <title>cnvd-2022-82666</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-82666</link>
      <description>cnvd-2022-82666</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-82666</guid>
    </item>
    <item>
      <title>EUVD-2026-234061</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-234061</link>
      <description>EUVD-2026-234061</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-234061</guid>
    </item>
    <item>
      <title>fkie_cve-2022-29226</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-29226</link>
      <description>&lt;p&gt;Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-29226</guid>
    </item>
    <item>
      <title>gsd-2022-29226</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-29226</link>
      <description>gsd-2022-29226</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-29226</guid>
    </item>
    <item>
      <title>RHSA-2022:5004 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.1.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:5004</link>
      <description>&lt;p&gt;golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString golang: cmd/go: misinterpretation of branch names can lead to incorrect access control golang: crypto/elliptic: IsOnCurve returns true for invalid field elements envoy: Segfault in GrpcHealthCheckerImpl envoy: Decompressors can be zip bombed envoy: oauth filter allows trivial bypass envoy: oauth filter calls continueDecoding() from within decodeHeaders() Istio: Unsafe memory access in metadata exchange.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString golang: cmd/go: misinterpretation of branch names can lead to incorrect access control golang: crypto/elliptic: IsOnCurve returns true for invalid field elements envoy: Segfault in GrpcHealthCheckerImpl envoy: Decompressors can be zip bombed envoy: oauth filter allows trivial bypass envoy: oauth filter calls continueDecoding() from within decodeHeaders() Istio: Unsafe memory access in metadata exchange.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:5004</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0288 — Red Hat OpenShift: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0288</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen, einen nicht näher spezifizierten Angriff durchzuführen, vertrauliche Informationen offenzulegen und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen, einen nicht näher spezifizierten Angriff durchzuführen, vertrauliche Informationen offenzulegen und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0288</guid>
    </item>
  </channel>
</rss>
