CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-11752

mediumcovered by 1 sourcefirst seen 2026-06-18
External Control of File Name or Path in xDS SDS DataSource Summary DataSourceStream in the :xds module resolves control-plane-supplied filename and environment_variable fields from SDS Secret resources without any allow-list or base-directory confinement. A semi-trusted or compromised xDS control plane (or an attacker who can MITM SDS responses) can read arbitrary local files and environment variables on the xDS client host. Affected component: xds/src/main/java/com/linecorp/armeria/xds/DataSourceStream.java Introduced in: Armeria 1.38.0 (commit b199560b10, "Add support for SDS", #6597) Affected versions: 1.38.0, 1.39.0 Impact A semi-trusted or compromised xDS control plane (or an attacker who can inject/MITM SDS responses) can: - Read arbitrary files on the xDS client host — TLS private keys, /etc/passwd, mounted Kubernetes service-account tokens, cloud credential files, etc. - Read arbitrary environment variables — AWS_SECRET_ACCESS_KEY, CI tokens, database credentials, etc. The read bytes are consumed as TLS key/cert/CA material. Combined with CWE-295 (silent disabling of upstream TLS peer verification), the exfiltrated secret can be presented to an attacker-chosen upstream, enabling data exfiltration. This is a confused-deputy / information-disclosure primitive driven entirely by control-plane-supplied configuration. Severity: High — arbitrary host-level file and environment variable read via control-plane-pushed configuration. Patches 1.40.0 The fix should: 1. Confine filename resolution to an operator-configured allow-list of base directories. After normalization, reject any path that escapes the allow-listed root. 2. **Gate environment_variable behind an explicit operator allow-list of permitted variable names. 3. Default to denying** both filename and environment_variable DataSources for control-plane-delivered (SDS) secrets unless explicitly enabled by the operator. This is stricter than upstream Envoy but appropriate when the control plane is

⚡ Watch CVE-2026-11752

Get an email if CVE-2026-11752 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-11752

CVE.org record

Embed the live status

CVE-2026-11752 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-11752 status](https://www.csirts.com/badge/CVE-2026-11752)](https://www.csirts.com/cve/CVE-2026-11752)