<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 09:36:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-268896</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-268896</link>
      <description>EUVD-2026-268896</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-268896</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26205</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26205</link>
      <description>&lt;p&gt;opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as authority components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served. Version 1.13.2-envoy-2 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as authority components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served. Version 1.13.2-envoy-2 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26205</guid>
    </item>
    <item>
      <title>GHSA-9f29-v6mm-pw6w — opa-envoy-plugin has an Authorization Bypass via Double-Slash Path Misinterpretation in input.parsed_path</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9f29-v6mm-pw6w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/open-policy-agent/opa-envoy-plugin&lt;/p&gt;
&lt;p&gt;A security vulnerability has been discovered in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as [authority](https://datatracker.ietf.org/doc/html/rfc3986#section-3.2) components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served.&lt;/p&gt;
&lt;p&gt;#### Attack example&lt;/p&gt;
&lt;p&gt;**HTTP request:**&lt;/p&gt;
&lt;p&gt;```
GET //admin/users HTTP/1.1
Host: example.com
```&lt;/p&gt;
&lt;p&gt;**Policy sees:**&lt;/p&gt;
&lt;p&gt;The leading `//admin` path segment is interpreted as an authority component, and dropped from `input.parsed_path` field:&lt;/p&gt;
&lt;p&gt;```json
{
  &amp;#34;parsed_path&amp;#34;: [&amp;#34;users&amp;#34;]
}
```&lt;/p&gt;
&lt;p&gt;**Backend receives:**&lt;/p&gt;
&lt;p&gt;`//admin/users` path, normalized to `/admin/users`.&lt;/p&gt;
&lt;p&gt;#### Affected Request Pattern Examples&lt;/p&gt;
&lt;p&gt;| Request path | `input.parsed_path` | `input.attributes.request.http.path` | Discrepancy |
| - | - | - | - |
| / | [&amp;#34;&amp;#34;] | / | ✅ None |
| //foo  | [&amp;#34;&amp;#34;] | //foo| ❌ Mismatch |
| /admin | [&amp;#34;admin&amp;#34;] | /admin | ✅ None |
| /admin/users | [&amp;#34;admin&amp;#34;, &amp;#34;users&amp;#34;] |  /admin/users | ✅ None |
| //admin/users  | [&amp;#34;users&amp;#34;] | //admin/users | ❌ Mismatch |&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Users are impacted if all the following conditions apply:&lt;/p&gt;
&lt;p&gt;1. Protected resources are path-hierarchical (e.g., `/admin/users` vs `/users`)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/open-policy-agent/opa-envoy-plugin&lt;/p&gt;
&lt;p&gt;A security vulnerability has been discovered in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as [authority](https://datatracker.ietf.org/doc/html/rfc3986#section-3.2) components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served.&lt;/p&gt;
&lt;p&gt;#### Attack example&lt;/p&gt;
&lt;p&gt;**HTTP request:**&lt;/p&gt;
&lt;p&gt;```
GET //admin/users HTTP/1.1
Host: example.com
```&lt;/p&gt;
&lt;p&gt;**Policy sees:**&lt;/p&gt;
&lt;p&gt;The leading `//admin` path segment is interpreted as an authority component, and dropped from `input.parsed_path` field:&lt;/p&gt;
&lt;p&gt;```json
{
  &amp;#34;parsed_path&amp;#34;: [&amp;#34;users&amp;#34;]
}
```&lt;/p&gt;
&lt;p&gt;**Backend receives:**&lt;/p&gt;
&lt;p&gt;`//admin/users` path, normalized to `/admin/users`.&lt;/p&gt;
&lt;p&gt;#### Affected Request Pattern Examples&lt;/p&gt;
&lt;p&gt;| Request path | `input.parsed_path` | `input.attributes.request.http.path` | Discrepancy |
| - | - | - | - |
| / | [&amp;#34;&amp;#34;] | / | ✅ None |
| //foo  | [&amp;#34;&amp;#34;] | //foo| ❌ Mismatch |
| /admin | [&amp;#34;admin&amp;#34;] | /admin | ✅ None |
| /admin/users | [&amp;#34;admin&amp;#34;, &amp;#34;users&amp;#34;] |  /admin/users | ✅ None |
| //admin/users  | [&amp;#34;users&amp;#34;] | //admin/users | ❌ Mismatch |&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Users are impacted if all the following conditions apply:&lt;/p&gt;
&lt;p&gt;1. Protected resources are path-hierarchical (e.g., `/admin/users` vs `/users`)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9f29-v6mm-pw6w</guid>
    </item>
  </channel>
</rss>
