<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Contour (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/contour.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/contour-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Contour (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:53 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-41246 – Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41246</guid>
    <pubDate>Thu, 23 Apr 2026 19:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41246</strong></p>
  <p>Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify HTTPProxy resources can craft a malicious value in spec.routes[].cookieRewritePolicies[].pathRewrite.value or spec.routes[].services[].cookieRewritePolicies[…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-36539 – Insecure permissions in contour v1.28.3 allows attackers to access sensitive dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36539</guid>
    <pubDate>Wed, 24 Jul 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-36539</strong></p>
  <p>Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-277</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32783 – Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32783</guid>
    <pubDate>Fri, 23 Jul 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32783</strong></p>
  <p>Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin interface, which Contour normally prevents from access outside the Envoy container. This can be used to shut down Envoy remotely (a denial of service), or to expose the existence of any Secret that Envoy is using for its c…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-441</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15127 – In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad acto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15127</guid>
    <pubDate>Wed, 05 Aug 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15127</strong></p>
  <p>In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown procedure includes flipping the readiness endpoint to false, which removes Envoy from the routing pool. When running Envoy…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18979 – An issue was discovered in the Ascensia Contour NEXT ONE application for Android...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18979</guid>
    <pubDate>Mon, 06 May 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18979</strong></p>
  <p>An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initialization vector is necessary for deciphering communications between this application and the backend server. This, in combination with retrieving any user's encrypted data from the Ascensia cloud through another vulnerability,…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18978 – An issue was discovered in the Ascensia Contour NEXT ONE application for Android...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18978</guid>
    <pubDate>Mon, 06 May 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18978</strong></p>
  <p>An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is necessary for deciphering communications between this application and the backend server. This, in combination with retrieving any user's encrypted data from the Ascensia cloud through another vulnerability, allows an att…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18977 – An issue was discovered in the Ascensia Contour NEXT ONE application for Android...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18977</guid>
    <pubDate>Mon, 06 May 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18977</strong></p>
  <p>An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reverse engineer the codebase to extract sensitive data that contributes to the disclosure of medical information of patients utilizing the Ascensia platform. This occurs because of weak obfuscation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18975 – An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18975</guid>
    <pubDate>Mon, 06 May 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18975</strong></p>
  <p>An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communications between the app and Ascensia backend servers because of a weak certificate-pinning implementation, leading to disclosure of medical information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8287 – FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8287</guid>
    <pubDate>Thu, 27 Apr 2017 00:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8287</strong></p>
  <p>FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8287">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
