<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:48:11 +0000</lastBuildDate>
    <item>
      <title>BIT-envoy-2026-26308 — Envoy has an RBAC Header Validation Bypass via Multi-Value Header Concatenation</title>
      <link>https://cve.radiocsirt.org/vuln/bit-envoy-2026-26308</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically &amp;#34;Deny&amp;#34; rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically &amp;#34;Deny&amp;#34; rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-envoy-2026-26308</guid>
    </item>
    <item>
      <title>EUVD-2026-275357</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275357</link>
      <description>EUVD-2026-275357</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275357</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26308</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26308</link>
      <description>&lt;p&gt;Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically &amp;#34;Deny&amp;#34; rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically &amp;#34;Deny&amp;#34; rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26308</guid>
    </item>
    <item>
      <title>GHSA-ghc4-35x6-crw5 — Envoy has RBAC Header Validation Bypass via Multi-Value Header Concatenation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ghc4-35x6-crw5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/envoyproxy/envoy&lt;/p&gt;
&lt;p&gt;## 1. Summary
The Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically &amp;#34;Deny&amp;#34; rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms.&lt;/p&gt;
&lt;p&gt;## 2. Attack Scenario
Consider an environment where an administrator wants to block external access to internal resources using a specific header flag.&lt;/p&gt;
&lt;p&gt;### Configuration
The Envoy proxy is configured with a **Deny** rule to reject requests containing the header `internal: true`.
* **Rule Type:** Exact Match
* **Target:** `internal` header must not equal `true`.&lt;/p&gt;
&lt;p&gt;### The Bypass Logic
1.  **Standard Request (Blocked):**
    * **Input:** `internal: true`
    * **Envoy Processing:** Sees string `&amp;#34;true&amp;#34;`.
    * **Result:** Match found. **Request Denied.**&lt;/p&gt;
&lt;p&gt;2.  **Exploit Request (Bypassed):**
    * **Input:**
        ```http
        internal: true
        internal: true
        ```
    * **Envoy Processing:** Concatenates values into `&amp;#34;true,true&amp;#34;`.
    * **Matcher Evaluation:** Does `&amp;#34;true,true&amp;#34;` equal `&amp;#34;true&amp;#34;`? **No.**
    * **Result:** The Deny rule fails to trigger. **Request Allowed.**&lt;/p&gt;
&lt;p&gt;## 3. Implications
* **RBAC Bypass:** Remote attackers can bypass configured access controls.
* **Unauthoriz…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/envoyproxy/envoy&lt;/p&gt;
&lt;p&gt;## 1. Summary
The Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically &amp;#34;Deny&amp;#34; rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms.&lt;/p&gt;
&lt;p&gt;## 2. Attack Scenario
Consider an environment where an administrator wants to block external access to internal resources using a specific header flag.&lt;/p&gt;
&lt;p&gt;### Configuration
The Envoy proxy is configured with a **Deny** rule to reject requests containing the header `internal: true`.
* **Rule Type:** Exact Match
* **Target:** `internal` header must not equal `true`.&lt;/p&gt;
&lt;p&gt;### The Bypass Logic
1.  **Standard Request (Blocked):**
    * **Input:** `internal: true`
    * **Envoy Processing:** Sees string `&amp;#34;true&amp;#34;`.
    * **Result:** Match found. **Request Denied.**&lt;/p&gt;
&lt;p&gt;2.  **Exploit Request (Bypassed):**
    * **Input:**
        ```http
        internal: true
        internal: true
        ```
    * **Envoy Processing:** Concatenates values into `&amp;#34;true,true&amp;#34;`.
    * **Matcher Evaluation:** Does `&amp;#34;true,true&amp;#34;` equal `&amp;#34;true&amp;#34;`? **No.**
    * **Result:** The Deny rule fails to trigger. **Request Allowed.**&lt;/p&gt;
&lt;p&gt;## 3. Implications
* **RBAC Bypass:** Remote attackers can bypass configured access controls.
* **Unauthoriz…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ghc4-35x6-crw5</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0704 — Google Cloud Platform Envoy Proxy, Istio und Service Mesh: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0704</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Google Cloud Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Google Cloud Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0704</guid>
    </item>
  </channel>
</rss>
