<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:42:59 +0000</lastBuildDate>
    <item>
      <title>BIT-envoy-2026-73546 — Envoy: Stored XSS in Admin Stats Interface (/stats?format=html)</title>
      <link>https://cve.radiocsirt.org/vuln/bit-envoy-2026-73546</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy&amp;#39;s /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component such as grpc_stats with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface&amp;#39;s origin and issue privileged same-origin requests. The relevant scope boundary is that the admin interface must be browser-accessible and an enabled component must persist attacker-influenced text in statistic names. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: envoy&lt;/p&gt;
&lt;p&gt;Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy&amp;#39;s /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component such as grpc_stats with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface&amp;#39;s origin and issue privileged same-origin requests. The relevant scope boundary is that the admin interface must be browser-accessible and an enabled component must persist attacker-influenced text in statistic names. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-envoy-2026-73546</guid>
    </item>
    <item>
      <title>EUVD-2026-373256</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-373256</link>
      <description>EUVD-2026-373256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-373256</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73546</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73546</link>
      <description>&lt;p&gt;Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy&amp;#39;s /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component such as grpc_stats with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface&amp;#39;s origin and issue privileged same-origin requests. The relevant scope boundary is that the admin interface must be browser-accessible and an enabled component must persist attacker-influenced text in statistic names. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy&amp;#39;s /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component such as grpc_stats with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface&amp;#39;s origin and issue privileged same-origin requests. The relevant scope boundary is that the admin interface must be browser-accessible and an enabled component must persist attacker-influenced text in statistic names. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73546</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11630-1 — istioctl-1.30.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11630-1</link>
      <description>&lt;p&gt;istioctl-1.30.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;istioctl-1.30.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11630-1</guid>
    </item>
    <item>
      <title>RHSA-2026:65106 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.0.15</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:65106</link>
      <description>&lt;p&gt;encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls envoy: envoy: ext_authz use-after-free after rejecting an HTTP request net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages envoy: envoy: path matching bypass via per-segment parameters not stripped by router envoy: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free envoy: envoy: stored XSS through dynamically generated stat names in admin interface envoy: envoy: ext_authz crash on CONNECT requests without :path pseudo-header envoy: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests envoy: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters envoy: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits envoy: envoy: path normalization bypass via dot/dot-dot segments with parameters envoy: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values e…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls envoy: envoy: ext_authz use-after-free after rejecting an HTTP request net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages envoy: envoy: path matching bypass via per-segment parameters not stripped by router envoy: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free envoy: envoy: stored XSS through dynamically generated stat names in admin interface envoy: envoy: ext_authz crash on CONNECT requests without :path pseudo-header envoy: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests envoy: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters envoy: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits envoy: envoy: path normalization bypass via dot/dot-dot segments with parameters envoy: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values e…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:65106</guid>
    </item>
  </channel>
</rss>
