<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:39:06 +0000</lastBuildDate>
    <item>
      <title>BIT-envoy-2026-26309 — Envoy has an off-by-one write in JsonEscaper::escapeString()</title>
      <link>https://cve.radiocsirt.org/vuln/bit-envoy-2026-26309</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write in Envoy::JsonEscaper::escapeString() can corrupt std::string null-termination, causing undefined behavior and potentially leading to crashes or out-of-bounds reads when the resulting string is later treated as a C-string. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write in Envoy::JsonEscaper::escapeString() can corrupt std::string null-termination, causing undefined behavior and potentially leading to crashes or out-of-bounds reads when the resulting string is later treated as a C-string. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-envoy-2026-26309</guid>
    </item>
    <item>
      <title>EUVD-2026-275356</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275356</link>
      <description>EUVD-2026-275356</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275356</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26309</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26309</link>
      <description>&lt;p&gt;Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write in Envoy::JsonEscaper::escapeString() can corrupt std::string null-termination, causing undefined behavior and potentially leading to crashes or out-of-bounds reads when the resulting string is later treated as a C-string. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write in Envoy::JsonEscaper::escapeString() can corrupt std::string null-termination, causing undefined behavior and potentially leading to crashes or out-of-bounds reads when the resulting string is later treated as a C-string. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26309</guid>
    </item>
    <item>
      <title>GHSA-56cj-wgg3-x943 — Envoy affected by off-by-one write in JsonEscaper::escapeString()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-56cj-wgg3-x943</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/envoyproxy/envoy&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An off-by-one write in Envoy::JsonEscaper::escapeString() can corrupt
  std::string null-termination, causing undefined behavior and potentially
  leading to crashes or out-of-bounds reads when the resulting string is later
  treated as a C-string.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The bug is in the control-character escaping path in source/common/common/
  json_escape_string.h:67.&lt;/p&gt;
&lt;p&gt;- The function pre-sizes result to the final length: std::string
    result(input.size() + required_size, &amp;#39;\\&amp;#39;);
  - For control characters (0x00..0x1f), it emits a JSON escape sequence of
    length 6: \u00XX.
  - It uses sprintf(&amp;amp;result[position + 1], &amp;#34;u%04x&amp;#34;, ...), which writes 5 chars +
    a trailing NUL (\0) starting at result[position + 1].
  - Then it does position += 6; and writes result[position] = &amp;#39;\\&amp;#39;; to overwrite
    the NUL.
  - If the control character occurs at the end of the output (e.g., the input
    ends with \x01), then after position += 6, position == result.size(), so
    result[position] is one past the end (off-by-one), violating std::string
    bounds/contract.&lt;/p&gt;
&lt;p&gt;Concretely, the problematic lines are:&lt;/p&gt;
&lt;p&gt;- source/common/common/json_escape_string.h:69 (sprintf(...))
  - source/common/common/json_escape_string.h:72 (result[position] = &amp;#39;\\&amp;#39;;)&lt;/p&gt;
&lt;p&gt;Potentially reachable from request-driven paths that escape untrusted data,
  e.g. invalid header reporting:&lt;/p&gt;
&lt;p&gt;- source/common/http/header_utility.cc:538 ~ source/common/http/
    header_utility.cc:546 (escapes invalid header ke…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/envoyproxy/envoy&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An off-by-one write in Envoy::JsonEscaper::escapeString() can corrupt
  std::string null-termination, causing undefined behavior and potentially
  leading to crashes or out-of-bounds reads when the resulting string is later
  treated as a C-string.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The bug is in the control-character escaping path in source/common/common/
  json_escape_string.h:67.&lt;/p&gt;
&lt;p&gt;- The function pre-sizes result to the final length: std::string
    result(input.size() + required_size, &amp;#39;\\&amp;#39;);
  - For control characters (0x00..0x1f), it emits a JSON escape sequence of
    length 6: \u00XX.
  - It uses sprintf(&amp;amp;result[position + 1], &amp;#34;u%04x&amp;#34;, ...), which writes 5 chars +
    a trailing NUL (\0) starting at result[position + 1].
  - Then it does position += 6; and writes result[position] = &amp;#39;\\&amp;#39;; to overwrite
    the NUL.
  - If the control character occurs at the end of the output (e.g., the input
    ends with \x01), then after position += 6, position == result.size(), so
    result[position] is one past the end (off-by-one), violating std::string
    bounds/contract.&lt;/p&gt;
&lt;p&gt;Concretely, the problematic lines are:&lt;/p&gt;
&lt;p&gt;- source/common/common/json_escape_string.h:69 (sprintf(...))
  - source/common/common/json_escape_string.h:72 (result[position] = &amp;#39;\\&amp;#39;;)&lt;/p&gt;
&lt;p&gt;Potentially reachable from request-driven paths that escape untrusted data,
  e.g. invalid header reporting:&lt;/p&gt;
&lt;p&gt;- source/common/http/header_utility.cc:538 ~ source/common/http/
    header_utility.cc:546 (escapes invalid header ke…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-56cj-wgg3-x943</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0704 — Google Cloud Platform Envoy Proxy, Istio und Service Mesh: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0704</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Google Cloud Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Google Cloud Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0704</guid>
    </item>
  </channel>
</rss>
