<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:03:13 +0000</lastBuildDate>
    <item>
      <title>BIT-envoy-2024-23326 — Envoy incorrectly accepts HTTP 200 response for entering upgrade mode</title>
      <link>https://cve.radiocsirt.org/vuln/bit-envoy-2024-23326</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into adding an upgrade header into a response. Per RFC https://www.rfc-editor.org/rfc/rfc7230#section-6.7 a server sends 101 when switching protocols. Envoy incorrectly accepts a 200 response from a server when requesting a protocol upgrade, but 200 does not indicate protocol switch. This opens up the possibility of request smuggling through Envoy if the server can be tricked into adding the upgrade header to the response.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into adding an upgrade header into a response. Per RFC https://www.rfc-editor.org/rfc/rfc7230#section-6.7 a server sends 101 when switching protocols. Envoy incorrectly accepts a 200 response from a server when requesting a protocol upgrade, but 200 does not indicate protocol switch. This opens up the possibility of request smuggling through Envoy if the server can be tricked into adding the upgrade header to the response.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-envoy-2024-23326</guid>
    </item>
    <item>
      <title>EUVD-2026-3999</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-3999</link>
      <description>EUVD-2026-3999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-3999</guid>
    </item>
    <item>
      <title>fkie_cve-2024-23326</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23326</link>
      <description>&lt;p&gt;Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into adding an upgrade header into a response. Per RFC https://www.rfc-editor.org/rfc/rfc7230#section-6.7 a server sends 101 when switching protocols. Envoy incorrectly accepts a 200 response from a server when requesting a protocol upgrade, but 200 does not indicate protocol switch. This opens up the possibility of request smuggling through Envoy if the server can be tricked into adding the upgrade header to the response.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into adding an upgrade header into a response. Per RFC https://www.rfc-editor.org/rfc/rfc7230#section-6.7 a server sends 101 when switching protocols. Envoy incorrectly accepts a 200 response from a server when requesting a protocol upgrade, but 200 does not indicate protocol switch. This opens up the possibility of request smuggling through Envoy if the server can be tricked into adding the upgrade header to the response.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-23326</guid>
    </item>
    <item>
      <title>gsd-2024-23326</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-23326</link>
      <description>gsd-2024-23326</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-23326</guid>
    </item>
    <item>
      <title>RHSA-2024:7725 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh Containers for 2.5.5</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:7725</link>
      <description>&lt;p&gt;envoy: Envoy incorrectly accepts HTTP 200 response for entering upgrade mode envoy: HTTP/2 CPU exhaustion due to CONTINUATION frame flood envoy: abnormal termination when using auto_sni with authority header longer than 255 characters envoy: Brotli decompressor infinite loop webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule send: Code Execution Vulnerability in Send Library serve-static: Improper Sanitization in serve-static body-parser: Denial of Service Vulnerability in body-parser envoy: Potential to manipulate `x-envoy` headers from external sources&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;envoy: Envoy incorrectly accepts HTTP 200 response for entering upgrade mode envoy: HTTP/2 CPU exhaustion due to CONTINUATION frame flood envoy: abnormal termination when using auto_sni with authority header longer than 255 characters envoy: Brotli decompressor infinite loop webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule send: Code Execution Vulnerability in Send Library serve-static: Improper Sanitization in serve-static body-parser: Denial of Service Vulnerability in body-parser envoy: Potential to manipulate `x-envoy` headers from external sources&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:7725</guid>
    </item>
  </channel>
</rss>
