<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:16:13 +0000</lastBuildDate>
    <item>
      <title>BIT-envoy-2026-48042 — Envoy: Stack overflow in destructor of highly nested JSON</title>
      <link>https://cve.radiocsirt.org/vuln/bit-envoy-2026-48042</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-envoy-2026-48042</guid>
    </item>
    <item>
      <title>EUVD-2026-331015</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331015</link>
      <description>EUVD-2026-331015</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331015</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48042</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48042</link>
      <description>&lt;p&gt;Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48042</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11141-1 — istioctl-1.30.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11141-1</link>
      <description>&lt;p&gt;istioctl-1.30.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;istioctl-1.30.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11141-1</guid>
    </item>
    <item>
      <title>RHSA-2026:49705 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.0.14</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:49705</link>
      <description>&lt;p&gt;crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries envoy: Envoy: Denial of Service via Connect protocol request envoy: Envoy: Null pointer deref in internal redirects envoy: Envoy: Denial of Service via deeply nested JSON objects Envoy: Envoy: Denial of Service via specially crafted zstd payload&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries envoy: Envoy: Denial of Service via Connect protocol request envoy: Envoy: Null pointer deref in internal redirects envoy: Envoy: Denial of Service via deeply nested JSON objects Envoy: Envoy: Denial of Service via specially crafted zstd payload&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:49705</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2048 — Google Cloud Service Mesh und Envoy Proxy: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2048</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Google Cloud Service Mesh und Envoy Proxy ausnutzen, um einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Google Cloud Service Mesh und Envoy Proxy ausnutzen, um einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2048</guid>
    </item>
  </channel>
</rss>
