VYPR

rpm package

opensuse/istioctl&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/istioctl&distro=openSUSE%20Tumbleweed

Vulnerabilities (35)

  • CVE-2026-73553HigSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix before matching but the RBAC url_path matcher e

  • CVE-2026-73551MedSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon parameters. A request such as /user/..;foo=bar/

  • CVE-2026-73511MedSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolon matrix parameters from each path segment

  • CVE-2026-73552HigSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semantics. A downstream client can p

  • CVE-2026-73550HigSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy copies every decoded HTTP/2 Host header value before discarding it when :authority is already present. The discarded value bypasses saveHeade

  • CVE-2026-73549MedSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addresses through addressAsString and Ipv6Instanc

  • CVE-2026-73548HigSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade. An unauthenticated HTTP/2 client can place

  • CVE-2026-73547HigSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove f

  • CVE-2026-73546HigSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML enco

  • CVE-2026-73513HigSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 codec accepts a response trailer HEADERS frame without END_STREAM. Envoy completes and deferred-deletes th

  • CVE-2026-73512HigSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream recreation, including an internal redirect,

  • CVE-2026-50572MedSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can retain a stale request callback after a request is rejected. When RawHttpClientImpl::onSuccess later

  • CVE-2026-48521MedSep 21, 2026
    affected < 1.30.4-1.1fixed 1.30.4-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while selecting an HTTP/3 connection pool without first c

  • CVE-2026-48090MedJun 26, 2026
    affected < 1.30.2-1.1fixed 1.30.2-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can leave an in-flight async token exchange attached to a downstream stream that has already been torn do

  • CVE-2026-47220HigJun 26, 2026
    affected < 1.30.2-1.1fixed 1.30.2-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIRST, it's possible to crash Envoy

  • CVE-2026-47205MedJun 26, 2026
    affected < 1.30.2-1.1fixed 1.30.2-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to a sudden segmentation fault exists in Envoy's ext_authz HTTP filter when processing per-route autho

  • CVE-2026-48743HigJun 26, 2026
    affected < 1.30.2-1.1fixed 1.30.2-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request that is complete at the transport layer (HEADERS with FIN / headers-only close) but still carries a

  • CVE-2026-48706MedJun 26, 2026
    affected < 1.30.2-1.1fixed 1.30.2-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP StatsD sink (TcpStatsdSink), where the thread-local flusher buffer can be overflowed by exceptionall

  • CVE-2026-48497MedJun 26, 2026
    affected < 1.30.2-1.1fixed 1.30.2-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or remote resolution for a name o

  • CVE-2026-48044HigJun 26, 2026
    affected < 1.30.2-1.1fixed 1.30.2-1.1

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability has been identified in Envoy's zstd decompressor implementation (ZstdDecompressorImpl). When zstd decompression is enable

Page 1 of 2