NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-11752
Summary

A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables without restriction, allowing a compromised or semi-trusted xDS control plane to read arbitrary local files and environment variables on the xDS client host.

Publication Date June 19, 2026, 3:17 p.m.
Registration Date June 27, 2026, 4:04 a.m.
Last Update June 23, 2026, 5:21 a.m.
Related information, measures and tools
Common Vulnerabilities List