{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-26205",
        "tracking": {
            "current_release_date": "2026-03-22T17:52:33.164788Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-26205",
            "initial_release_date": "2026-02-18T15:42:57.301375Z",
            "revision_history": [
                {
                    "date": "2026-02-18T15:42:57.301375Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-02-18T15:43:05.985159Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-19T00:12:32.025788Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-02-19T00:12:40.965491Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-19T20:49:17.017982Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-02-19T20:49:28.696556Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-19T21:28:00.339756Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-02-19T21:28:08.591339Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-19T21:38:55.567633Z",
                    "number": "9",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-02-19T22:39:44.124538Z",
                    "number": "10",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-02-20T14:13:44.434668Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-20T14:13:46.424426Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-23T00:12:35.712746Z",
                    "number": "13",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-02-23T00:12:38.504765Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-24T00:12:47.164799Z",
                    "number": "15",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| References created (4)."
                },
                {
                    "date": "2026-02-24T00:12:54.170156Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-26T03:49:15.236435Z",
                    "number": "17",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (131).| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T03:49:34.262195Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-16T15:00:28.694310Z",
                    "number": "19",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2026-03-16T15:00:32.448694Z",
                    "number": "20",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:44:31.742750Z",
                    "number": "21",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:44:34.364787Z",
                    "number": "22",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T18:15:04.021363Z",
                    "number": "23",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T19:14:29.334066Z",
                    "number": "24",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (6).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T19:14:31.288078Z",
                    "number": "25",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "25"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.13.2-envoy-2",
                                "product": {
                                    "name": "vers:unknown/1.13.2-envoy-2",
                                    "product_id": "CSAFPID-5875602"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.13.2-envoy-2",
                                "product": {
                                    "name": "vers:unknown/<1.13.2-envoy-2",
                                    "product_id": "CSAFPID-5875603"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "go/github.com/open-policy-agent/opa-envoy-plugin"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.24.0-envoy-8",
                                "product": {
                                    "name": "vers:unknown/0.24.0-envoy-8",
                                    "product_id": "CSAFPID-5724981"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.13.2-envoy-2",
                                "product": {
                                    "name": "vers:unknown/<1.13.2-envoy-2",
                                    "product_id": "CSAFPID-5641463"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<1.13.2-envoy-2",
                                "product": {
                                    "name": "vers:unknown/>=0|<1.13.2-envoy-2",
                                    "product_id": "CSAFPID-5630934"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/proxy_init-v7",
                                "product": {
                                    "name": "vers:unknown/proxy_init-v7",
                                    "product_id": "CSAFPID-5724982"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/proxy_init-v8",
                                "product": {
                                    "name": "vers:unknown/proxy_init-v8",
                                    "product_id": "CSAFPID-5724983"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.10.6",
                                "product": {
                                    "name": "vers:unknown/v0.10.6",
                                    "product_id": "CSAFPID-5724984"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.10.7",
                                "product": {
                                    "name": "vers:unknown/v0.10.7",
                                    "product_id": "CSAFPID-5724985"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.12.0",
                                "product": {
                                    "name": "vers:unknown/v0.12.0",
                                    "product_id": "CSAFPID-5724986"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.12.1",
                                "product": {
                                    "name": "vers:unknown/v0.12.1",
                                    "product_id": "CSAFPID-5724987"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.13.2",
                                "product": {
                                    "name": "vers:unknown/v0.13.2",
                                    "product_id": "CSAFPID-5724988"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.14.2",
                                "product": {
                                    "name": "vers:unknown/v0.14.2",
                                    "product_id": "CSAFPID-5724989"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.21.0",
                                "product": {
                                    "name": "vers:unknown/v0.21.0",
                                    "product_id": "CSAFPID-5724990"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.21.1",
                                "product": {
                                    "name": "vers:unknown/v0.21.1",
                                    "product_id": "CSAFPID-5724991"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.22.0",
                                "product": {
                                    "name": "vers:unknown/v0.22.0",
                                    "product_id": "CSAFPID-5724992"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.23.0",
                                "product": {
                                    "name": "vers:unknown/v0.23.0",
                                    "product_id": "CSAFPID-5724993"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.23.1",
                                "product": {
                                    "name": "vers:unknown/v0.23.1",
                                    "product_id": "CSAFPID-5724994"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.23.2",
                                "product": {
                                    "name": "vers:unknown/v0.23.2",
                                    "product_id": "CSAFPID-5724995"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.0",
                                "product": {
                                    "name": "vers:unknown/v0.24.0",
                                    "product_id": "CSAFPID-5724996"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.0-envoy-1",
                                "product": {
                                    "name": "vers:unknown/v0.24.0-envoy-1",
                                    "product_id": "CSAFPID-5724997"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.0-envoy-11",
                                "product": {
                                    "name": "vers:unknown/v0.24.0-envoy-11",
                                    "product_id": "CSAFPID-5724998"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.0-envoy-3",
                                "product": {
                                    "name": "vers:unknown/v0.24.0-envoy-3",
                                    "product_id": "CSAFPID-5724999"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.0-envoy-4",
                                "product": {
                                    "name": "vers:unknown/v0.24.0-envoy-4",
                                    "product_id": "CSAFPID-5725000"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.0-envoy-5",
                                "product": {
                                    "name": "vers:unknown/v0.24.0-envoy-5",
                                    "product_id": "CSAFPID-5725001"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.0-envoy-7",
                                "product": {
                                    "name": "vers:unknown/v0.24.0-envoy-7",
                                    "product_id": "CSAFPID-5725002"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.0-envoy-8",
                                "product": {
                                    "name": "vers:unknown/v0.24.0-envoy-8",
                                    "product_id": "CSAFPID-5725003"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.25.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.25.0-envoy",
                                    "product_id": "CSAFPID-5725004"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.25.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.25.1-envoy",
                                    "product_id": "CSAFPID-5725005"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.25.2-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.25.2-envoy",
                                    "product_id": "CSAFPID-5725006"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.25.2-envoy-3",
                                "product": {
                                    "name": "vers:unknown/v0.25.2-envoy-3",
                                    "product_id": "CSAFPID-5725007"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.26.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.26.0-envoy",
                                    "product_id": "CSAFPID-5725008"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.26.0-envoy-2",
                                "product": {
                                    "name": "vers:unknown/v0.26.0-envoy-2",
                                    "product_id": "CSAFPID-5725009"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.26.0-envoy-6",
                                "product": {
                                    "name": "vers:unknown/v0.26.0-envoy-6",
                                    "product_id": "CSAFPID-5725010"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.27.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.27.0-envoy",
                                    "product_id": "CSAFPID-5725011"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.27.0-envoy-4",
                                "product": {
                                    "name": "vers:unknown/v0.27.0-envoy-4",
                                    "product_id": "CSAFPID-5725012"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.27.0-envoy-5",
                                "product": {
                                    "name": "vers:unknown/v0.27.0-envoy-5",
                                    "product_id": "CSAFPID-5725013"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.27.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.27.1-envoy",
                                    "product_id": "CSAFPID-5725014"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.28.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.28.0-envoy",
                                    "product_id": "CSAFPID-5725015"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.29.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.29.1-envoy",
                                    "product_id": "CSAFPID-5725016"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.29.4-envoy-2",
                                "product": {
                                    "name": "vers:unknown/v0.29.4-envoy-2",
                                    "product_id": "CSAFPID-5725017"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.29.4-envoy-3",
                                "product": {
                                    "name": "vers:unknown/v0.29.4-envoy-3",
                                    "product_id": "CSAFPID-5725018"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.30.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.30.1-envoy",
                                    "product_id": "CSAFPID-5725019"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.30.1-envoy-5",
                                "product": {
                                    "name": "vers:unknown/v0.30.1-envoy-5",
                                    "product_id": "CSAFPID-5725020"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.30.2-envoy-1",
                                "product": {
                                    "name": "vers:unknown/v0.30.2-envoy-1",
                                    "product_id": "CSAFPID-5725021"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.31.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.31.0-envoy",
                                    "product_id": "CSAFPID-5725022"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.32.0-envoy-4",
                                "product": {
                                    "name": "vers:unknown/v0.32.0-envoy-4",
                                    "product_id": "CSAFPID-5725023"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.32.1-envoy-1",
                                "product": {
                                    "name": "vers:unknown/v0.32.1-envoy-1",
                                    "product_id": "CSAFPID-5725024"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.33.1-envoy-2",
                                "product": {
                                    "name": "vers:unknown/v0.33.1-envoy-2",
                                    "product_id": "CSAFPID-5725025"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.33.1-envoy-3",
                                "product": {
                                    "name": "vers:unknown/v0.33.1-envoy-3",
                                    "product_id": "CSAFPID-5725026"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.34.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.34.0-envoy",
                                    "product_id": "CSAFPID-5725027"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.34.2-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.34.2-envoy",
                                    "product_id": "CSAFPID-5725028"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.35.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.35.0-envoy",
                                    "product_id": "CSAFPID-5725029"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.35.0-envoy-1",
                                "product": {
                                    "name": "vers:unknown/v0.35.0-envoy-1",
                                    "product_id": "CSAFPID-5725030"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.35.0-envoy-7",
                                "product": {
                                    "name": "vers:unknown/v0.35.0-envoy-7",
                                    "product_id": "CSAFPID-5725031"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.36.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.36.0-envoy",
                                    "product_id": "CSAFPID-5725032"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.36.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.36.1-envoy",
                                    "product_id": "CSAFPID-5725033"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.37.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.37.1-envoy",
                                    "product_id": "CSAFPID-5725034"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.37.2-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.37.2-envoy",
                                    "product_id": "CSAFPID-5725035"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.38.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.38.0-envoy",
                                    "product_id": "CSAFPID-5725036"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.38.1-envoy-3",
                                "product": {
                                    "name": "vers:unknown/v0.38.1-envoy-3",
                                    "product_id": "CSAFPID-5725037"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.39.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.39.0-envoy",
                                    "product_id": "CSAFPID-5725038"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.40.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.40.0-envoy",
                                    "product_id": "CSAFPID-5725039"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.41.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.41.0-envoy",
                                    "product_id": "CSAFPID-5725040"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.42.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.42.0-envoy",
                                    "product_id": "CSAFPID-5725041"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.42.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.42.1-envoy",
                                    "product_id": "CSAFPID-5725042"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.43.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.43.0-envoy",
                                    "product_id": "CSAFPID-5725043"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.44.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.44.0-envoy",
                                    "product_id": "CSAFPID-5725044"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.45.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.45.0-envoy",
                                    "product_id": "CSAFPID-5725045"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.45.0-envoy-10",
                                "product": {
                                    "name": "vers:unknown/v0.45.0-envoy-10",
                                    "product_id": "CSAFPID-5725046"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.46.1",
                                "product": {
                                    "name": "vers:unknown/v0.46.1",
                                    "product_id": "CSAFPID-5725047"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.46.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.46.1-envoy",
                                    "product_id": "CSAFPID-5725048"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.47.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.47.0-envoy",
                                    "product_id": "CSAFPID-5725049"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.47.2-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.47.2-envoy",
                                    "product_id": "CSAFPID-5725050"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.47.3-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.47.3-envoy",
                                    "product_id": "CSAFPID-5725051"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.47.4-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.47.4-envoy",
                                    "product_id": "CSAFPID-5725052"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.48.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.48.0-envoy",
                                    "product_id": "CSAFPID-5725053"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.49.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.49.0-envoy",
                                    "product_id": "CSAFPID-5725054"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.49.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.49.1-envoy",
                                    "product_id": "CSAFPID-5725055"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.49.2-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.49.2-envoy",
                                    "product_id": "CSAFPID-5725056"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.50.0-envoy-1",
                                "product": {
                                    "name": "vers:unknown/v0.50.0-envoy-1",
                                    "product_id": "CSAFPID-5725057"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.50.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.50.1-envoy",
                                    "product_id": "CSAFPID-5725058"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.50.2-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.50.2-envoy",
                                    "product_id": "CSAFPID-5725059"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.51.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.51.0-envoy",
                                    "product_id": "CSAFPID-5725060"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.52.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.52.0-envoy",
                                    "product_id": "CSAFPID-5725061"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.53.0-envoy-1",
                                "product": {
                                    "name": "vers:unknown/v0.53.0-envoy-1",
                                    "product_id": "CSAFPID-5725062"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.53.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.53.1-envoy",
                                    "product_id": "CSAFPID-5725063"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.54.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.54.0-envoy",
                                    "product_id": "CSAFPID-5725064"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.55.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.55.0-envoy",
                                    "product_id": "CSAFPID-5725065"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.56.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.56.0-envoy",
                                    "product_id": "CSAFPID-5725066"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.56.0-envoy-3",
                                "product": {
                                    "name": "vers:unknown/v0.56.0-envoy-3",
                                    "product_id": "CSAFPID-5725067"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.57.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.57.0-envoy",
                                    "product_id": "CSAFPID-5725068"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.57.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.57.1-envoy",
                                    "product_id": "CSAFPID-5725069"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.57.1-envoy-3",
                                "product": {
                                    "name": "vers:unknown/v0.57.1-envoy-3",
                                    "product_id": "CSAFPID-5725070"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.58.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.58.0-envoy",
                                    "product_id": "CSAFPID-5725071"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.59.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.59.0-envoy",
                                    "product_id": "CSAFPID-5725072"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.60.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.60.0-envoy",
                                    "product_id": "CSAFPID-5725073"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.61.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.61.0-envoy",
                                    "product_id": "CSAFPID-5725074"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.62.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.62.0-envoy",
                                    "product_id": "CSAFPID-5725075"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.62.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.62.1-envoy",
                                    "product_id": "CSAFPID-5725076"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.62.1-envoy-4",
                                "product": {
                                    "name": "vers:unknown/v0.62.1-envoy-4",
                                    "product_id": "CSAFPID-5725077"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.63.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.63.0-envoy",
                                    "product_id": "CSAFPID-5725078"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.64.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.64.0-envoy",
                                    "product_id": "CSAFPID-5725079"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.64.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.64.1-envoy",
                                    "product_id": "CSAFPID-5725080"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.65.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.65.0-envoy",
                                    "product_id": "CSAFPID-5725081"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.66.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.66.0-envoy",
                                    "product_id": "CSAFPID-5725082"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.66.0-envoy-2",
                                "product": {
                                    "name": "vers:unknown/v0.66.0-envoy-2",
                                    "product_id": "CSAFPID-5725083"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.67.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.67.0-envoy",
                                    "product_id": "CSAFPID-5725084"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.67.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.67.1-envoy",
                                    "product_id": "CSAFPID-5725085"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.68.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.68.0-envoy",
                                    "product_id": "CSAFPID-5725086"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.68.0-envoy-2",
                                "product": {
                                    "name": "vers:unknown/v0.68.0-envoy-2",
                                    "product_id": "CSAFPID-5725087"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.68.0-envoy-3",
                                "product": {
                                    "name": "vers:unknown/v0.68.0-envoy-3",
                                    "product_id": "CSAFPID-5725088"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.68.0-envoy-4",
                                "product": {
                                    "name": "vers:unknown/v0.68.0-envoy-4",
                                    "product_id": "CSAFPID-5725089"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.69.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.69.0-envoy",
                                    "product_id": "CSAFPID-5725090"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.70.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v0.70.0-envoy",
                                    "product_id": "CSAFPID-5725091"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.70.0-envoy-1",
                                "product": {
                                    "name": "vers:unknown/v0.70.0-envoy-1",
                                    "product_id": "CSAFPID-5725092"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.0.0-envoy",
                                    "product_id": "CSAFPID-5725093"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.0-envoy-1",
                                "product": {
                                    "name": "vers:unknown/v1.1.0-envoy-1",
                                    "product_id": "CSAFPID-5725094"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.10.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.10.0-envoy",
                                    "product_id": "CSAFPID-5725095"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.11.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.11.0-envoy",
                                    "product_id": "CSAFPID-5725096"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.11.1-envoy-3",
                                "product": {
                                    "name": "vers:unknown/v1.11.1-envoy-3",
                                    "product_id": "CSAFPID-5725097"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.12.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.12.0-envoy",
                                    "product_id": "CSAFPID-5725098"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.12.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.12.1-envoy",
                                    "product_id": "CSAFPID-5725099"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.12.2-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.12.2-envoy",
                                    "product_id": "CSAFPID-5725100"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.13.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.13.0-envoy",
                                    "product_id": "CSAFPID-5725101"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.13.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.13.1-envoy",
                                    "product_id": "CSAFPID-5725102"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.0-envoy-2",
                                "product": {
                                    "name": "vers:unknown/v1.2.0-envoy-2",
                                    "product_id": "CSAFPID-5725103"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.3.0-envoy-1",
                                "product": {
                                    "name": "vers:unknown/v1.3.0-envoy-1",
                                    "product_id": "CSAFPID-5725104"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4.2-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.4.2-envoy",
                                    "product_id": "CSAFPID-5725105"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.5.0-envoy-4",
                                "product": {
                                    "name": "vers:unknown/v1.5.0-envoy-4",
                                    "product_id": "CSAFPID-5725106"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.5.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.5.1-envoy",
                                    "product_id": "CSAFPID-5725107"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.6.0-envoy-2",
                                "product": {
                                    "name": "vers:unknown/v1.6.0-envoy-2",
                                    "product_id": "CSAFPID-5725108"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.7.1-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.7.1-envoy",
                                    "product_id": "CSAFPID-5725109"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.8.0-envoy",
                                    "product_id": "CSAFPID-5725110"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.9.0-envoy",
                                "product": {
                                    "name": "vers:unknown/v1.9.0-envoy",
                                    "product_id": "CSAFPID-5725111"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "opa-envoy-plugin"
                    }
                ],
                "category": "vendor",
                "name": "open-policy-agent"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-26205",
            "cwe": {
                "id": "CWE-863",
                "name": "Incorrect Authorization"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "A security vulnerability has been discovered in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as [authority](https://datatracker.ietf.org/doc/html/rfc3986#section-3.2) components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served.\n\n#### Attack example\n\n**HTTP request:**\n\n```\nGET //admin/users HTTP/1.1\nHost: example.com\n```\n\n**Policy sees:**\n\nThe leading `//admin` path segment is interpreted as an authority component, and dropped from `input.parsed_path` field:\n\n\n```json\n{\n  \"parsed_path\": [\"users\"]\n}\n```\n\n**Backend receives:**\n\n`//admin/users` path, normalized to `/admin/users`.\n\n#### Affected Request Pattern Examples\n\n| Request path | `input.parsed_path` | `input.attributes.request.http.path` | Discrepancy |\n| - | - | - | - |\n| / | [\"\"] | / | ✅ None |\n| //foo  | [\"\"] | //foo| ❌ Mismatch |\n| /admin | [\"admin\"] | /admin | ✅ None |\n| /admin/users | [\"admin\", \"users\"] |  /admin/users | ✅ None |\n| //admin/users  | [\"users\"] | //admin/users | ❌ Mismatch |\n\n### Impact\n\nUsers are impacted if all the following conditions apply:\n\n1. Protected resources are path-hierarchical (e.g., `/admin/users` vs `/users`)\n2. Authorization policies use `input.parsed_path` for path-based decisions\n3. Backend servers apply lenient path normalization\n\n### Patches\n\nGo: `v1.13.2-envoy-2`\nDocker: `1.13.2-envoy-2`, `1.13.2-envoy-2-static`\n\n### Workarounds\n\nUsers who cannot immediately upgrade opa-envoy-plugin are recommended to apply one, or more, of the workarrounds described below.\n\n#### 1. Enable the `merge_slashes` Envoy configuration option\n\nAs per [Envoy best practices](https://www.envoyproxy.io/docs/envoy/v1.37.0/configuration/best_practices/edge.html), enabling the [merge_slashes](https://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/filters/network/http_connection_manager/v3/http_connection_manager.proto#envoy-v3-api-field-extensions-filters-network-http-connection-manager-v3-httpconnectionmanager-merge-slashes) configuration option in Envoy will remove redundant slashes from the request path before filtering is applied, effectively mitigating the `input.parsed_path` issue described in this advisory.\n\n\n#### 2. Use `input.attributes.request.http.path` instead of `input.parsed_path` in policies\n\nThe `input.attributes.request.http.path` field contains the unprocessed, raw request path. Users are recommended to update any policy using `input.parsed_path` to instead use the `input.attributes.request.http.path` field.\n\n##### Example ####\n\n```rego\npackage example\n\n# Use instead of input.parsed_path\nparsed_path := split(                                        # tokenize into array\n\ttrim_left(                                               # drop leading slashes\n\t\turlquery.decode(input.attributes.request.http.path), # url-decode the path\n\t\t\"/\",\n\t),\n\t\"/\",\n)\n```",
                    "title": "github - https://github.com/advisories/GHSA-9f29-v6mm-pw6w"
                },
                {
                    "category": "description",
                    "text": "A security vulnerability has been discovered in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as [authority](https://datatracker.ietf.org/doc/html/rfc3986#section-3.2) components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served.\n\n#### Attack example\n\n**HTTP request:**\n\n```\nGET //admin/users HTTP/1.1\nHost: example.com\n```\n\n**Policy sees:**\n\nThe leading `//admin` path segment is interpreted as an authority component, and dropped from `input.parsed_path` field:\n\n\n```json\n{\n  \"parsed_path\": [\"users\"]\n}\n```\n\n**Backend receives:**\n\n`//admin/users` path, normalized to `/admin/users`.\n\n#### Affected Request Pattern Examples\n\n| Request path | `input.parsed_path` | `input.attributes.request.http.path` | Discrepancy |\n| - | - | - | - |\n| / | [\"\"] | / | ✅ None |\n| //foo  | [\"\"] | //foo| ❌ Mismatch |\n| /admin | [\"admin\"] | /admin | ✅ None |\n| /admin/users | [\"admin\", \"users\"] |  /admin/users | ✅ None |\n| //admin/users  | [\"users\"] | //admin/users | ❌ Mismatch |\n\n### Impact\n\nUsers are impacted if all the following conditions apply:\n\n1. Protected resources are path-hierarchical (e.g., `/admin/users` vs `/users`)\n2. Authorization policies use `input.parsed_path` for path-based decisions\n3. Backend servers apply lenient path normalization\n\n### Patches\n\nGo: `v1.13.2-envoy-2`\nDocker: `1.13.2-envoy-2`, `1.13.2-envoy-2-static`\n\n### Workarounds\n\nUsers who cannot immediately upgrade opa-envoy-plugin are recommended to apply one, or more, of the workarrounds described below.\n\n#### 1. Enable the `merge_slashes` Envoy configuration option\n\nAs per [Envoy best practices](https://www.envoyproxy.io/docs/envoy/v1.37.0/configuration/best_practices/edge.html), enabling the [merge_slashes](https://www.envoyproxy.io/docs/envoy/latest/api-v3/extensions/filters/network/http_connection_manager/v3/http_connection_manager.proto#envoy-v3-api-field-extensions-filters-network-http-connection-manager-v3-httpconnectionmanager-merge-slashes) configuration option in Envoy will remove redundant slashes from the request path before filtering is applied, effectively mitigating the `input.parsed_path` issue described in this advisory.\n\n\n#### 2. Use `input.attributes.request.http.path` instead of `input.parsed_path` in policies\n\nThe `input.attributes.request.http.path` field contains the unprocessed, raw request path. Users are recommended to update any policy using `input.parsed_path` to instead use the `input.attributes.request.http.path` field.\n\n##### Example ####\n\n```rego\npackage example\n\n# Use instead of input.parsed_path\nparsed_path := split(                                        # tokenize into array\n\ttrim_left(                                               # drop leading slashes\n\t\turlquery.decode(input.attributes.request.http.path), # url-decode the path\n\t\t\"/\",\n\t),\n\t\"/\",\n)\n```",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGHSA-9f29-v6mm-pw6w.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as authority components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served. Version 1.13.2-envoy-2 fixes the issue.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-26205"
                },
                {
                    "category": "description",
                    "text": "opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as authority components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served. Version 1.13.2-envoy-2 fixes the issue.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-26205"
                },
                {
                    "category": "description",
                    "text": "opa-envoy-plugin has an Authorization Bypass via Double-Slash Path Misinterpretation in input.parsed_path in github.com/open-policy-agent/opa-envoy-plugin",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGO-2026-4506.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as authority components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served. Version 1.13.2-envoy-2 fixes the issue.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-26205.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as authority components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served. Version 1.13.2-envoy-2 fixes the issue.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-26205"
                },
                {
                    "category": "description",
                    "text": "A security vulnerability has been discovered in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as [authority](https://datatracker.ietf.org/doc/html/rfc3986#section-3.2) components, and therefore dropping them from the parsed path. This creates a path interpretation mismatch between authorization policies and backend servers, enabling attackers to bypass access controls by crafting requests where the authorization filter evaluates a different path than the one ultimately served.",
                    "title": "gitlab - https://gitlab.com/api/v4/projects/25847700/repository/files/go%2Fgithub.com%2Fopen-policy-agent%2Fopa-envoy-plugin%2FCVE-2026-26205.yml/raw"
                },
                {
                    "category": "other",
                    "text": "0.00211",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "7.1",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.2",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to CWE-863 (Incorrect Authorization)",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "There is cwe data available from source Nvd",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-5875602"
                ],
                "known_affected": [
                    "CSAFPID-5630934",
                    "CSAFPID-5641463",
                    "CSAFPID-5724981",
                    "CSAFPID-5724982",
                    "CSAFPID-5724983",
                    "CSAFPID-5724984",
                    "CSAFPID-5724985",
                    "CSAFPID-5724986",
                    "CSAFPID-5724987",
                    "CSAFPID-5724988",
                    "CSAFPID-5724989",
                    "CSAFPID-5724990",
                    "CSAFPID-5724991",
                    "CSAFPID-5724992",
                    "CSAFPID-5724993",
                    "CSAFPID-5724994",
                    "CSAFPID-5724995",
                    "CSAFPID-5724996",
                    "CSAFPID-5724997",
                    "CSAFPID-5724998",
                    "CSAFPID-5724999",
                    "CSAFPID-5725000",
                    "CSAFPID-5725001",
                    "CSAFPID-5725002",
                    "CSAFPID-5725003",
                    "CSAFPID-5725004",
                    "CSAFPID-5725005",
                    "CSAFPID-5725006",
                    "CSAFPID-5725007",
                    "CSAFPID-5725008",
                    "CSAFPID-5725009",
                    "CSAFPID-5725010",
                    "CSAFPID-5725011",
                    "CSAFPID-5725012",
                    "CSAFPID-5725013",
                    "CSAFPID-5725014",
                    "CSAFPID-5725015",
                    "CSAFPID-5725016",
                    "CSAFPID-5725017",
                    "CSAFPID-5725018",
                    "CSAFPID-5725019",
                    "CSAFPID-5725020",
                    "CSAFPID-5725021",
                    "CSAFPID-5725022",
                    "CSAFPID-5725023",
                    "CSAFPID-5725024",
                    "CSAFPID-5725025",
                    "CSAFPID-5725026",
                    "CSAFPID-5725027",
                    "CSAFPID-5725028",
                    "CSAFPID-5725029",
                    "CSAFPID-5725030",
                    "CSAFPID-5725031",
                    "CSAFPID-5725032",
                    "CSAFPID-5725033",
                    "CSAFPID-5725034",
                    "CSAFPID-5725035",
                    "CSAFPID-5725036",
                    "CSAFPID-5725037",
                    "CSAFPID-5725038",
                    "CSAFPID-5725039",
                    "CSAFPID-5725040",
                    "CSAFPID-5725041",
                    "CSAFPID-5725042",
                    "CSAFPID-5725043",
                    "CSAFPID-5725044",
                    "CSAFPID-5725045",
                    "CSAFPID-5725046",
                    "CSAFPID-5725047",
                    "CSAFPID-5725048",
                    "CSAFPID-5725049",
                    "CSAFPID-5725050",
                    "CSAFPID-5725051",
                    "CSAFPID-5725052",
                    "CSAFPID-5725053",
                    "CSAFPID-5725054",
                    "CSAFPID-5725055",
                    "CSAFPID-5725056",
                    "CSAFPID-5725057",
                    "CSAFPID-5725058",
                    "CSAFPID-5725059",
                    "CSAFPID-5725060",
                    "CSAFPID-5725061",
                    "CSAFPID-5725062",
                    "CSAFPID-5725063",
                    "CSAFPID-5725064",
                    "CSAFPID-5725065",
                    "CSAFPID-5725066",
                    "CSAFPID-5725067",
                    "CSAFPID-5725068",
                    "CSAFPID-5725069",
                    "CSAFPID-5725070",
                    "CSAFPID-5725071",
                    "CSAFPID-5725072",
                    "CSAFPID-5725073",
                    "CSAFPID-5725074",
                    "CSAFPID-5725075",
                    "CSAFPID-5725076",
                    "CSAFPID-5725077",
                    "CSAFPID-5725078",
                    "CSAFPID-5725079",
                    "CSAFPID-5725080",
                    "CSAFPID-5725081",
                    "CSAFPID-5725082",
                    "CSAFPID-5725083",
                    "CSAFPID-5725084",
                    "CSAFPID-5725085",
                    "CSAFPID-5725086",
                    "CSAFPID-5725087",
                    "CSAFPID-5725088",
                    "CSAFPID-5725089",
                    "CSAFPID-5725090",
                    "CSAFPID-5725091",
                    "CSAFPID-5725092",
                    "CSAFPID-5725093",
                    "CSAFPID-5725094",
                    "CSAFPID-5725095",
                    "CSAFPID-5725096",
                    "CSAFPID-5725097",
                    "CSAFPID-5725098",
                    "CSAFPID-5725099",
                    "CSAFPID-5725100",
                    "CSAFPID-5725101",
                    "CSAFPID-5725102",
                    "CSAFPID-5725103",
                    "CSAFPID-5725104",
                    "CSAFPID-5725105",
                    "CSAFPID-5725106",
                    "CSAFPID-5725107",
                    "CSAFPID-5725108",
                    "CSAFPID-5725109",
                    "CSAFPID-5725110",
                    "CSAFPID-5725111",
                    "CSAFPID-5875603"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-9f29-v6mm-pw6w"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-9f29-v6mm-pw6w"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGHSA-9f29-v6mm-pw6w.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-26205"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/26xxx/CVE-2026-26205.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26205"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-26205"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-26205"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGO-2026-4506.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-26205.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-26205"
                },
                {
                    "category": "external",
                    "summary": "Source - gitlab",
                    "url": "https://gitlab.com/api/v4/projects/25847700/repository/files/go%2Fgithub.com%2Fopen-policy-agent%2Fopa-envoy-plugin%2FCVE-2026-26205.yml/raw"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv",
                    "url": "https://github.com/open-policy-agent/opa-envoy-plugin/security/advisories/GHSA-9f29-v6mm-pw6w"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv",
                    "url": "https://github.com/open-policy-agent/opa-envoy-plugin/commit/58c44d4ec408d5852d1d0287599e7d5c5e2bc5c3"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv",
                    "url": "https://github.com/open-policy-agent/opa-envoy-plugin/releases/tag/v1.13.2-envoy-2"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab",
                    "url": "https://github.com/advisories/GHSA-9f29-v6mm-pw6w"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26205"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26205.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - gitlab",
                    "url": "https://github.com/open-policy-agent/opa-envoy-plugin"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-5630934",
                        "CSAFPID-5641463",
                        "CSAFPID-5724981",
                        "CSAFPID-5724982",
                        "CSAFPID-5724983",
                        "CSAFPID-5724984",
                        "CSAFPID-5724985",
                        "CSAFPID-5724986",
                        "CSAFPID-5724987",
                        "CSAFPID-5724988",
                        "CSAFPID-5724989",
                        "CSAFPID-5724990",
                        "CSAFPID-5724991",
                        "CSAFPID-5724992",
                        "CSAFPID-5724993",
                        "CSAFPID-5724994",
                        "CSAFPID-5724995",
                        "CSAFPID-5724996",
                        "CSAFPID-5724997",
                        "CSAFPID-5724998",
                        "CSAFPID-5724999",
                        "CSAFPID-5725000",
                        "CSAFPID-5725001",
                        "CSAFPID-5725002",
                        "CSAFPID-5725003",
                        "CSAFPID-5725004",
                        "CSAFPID-5725005",
                        "CSAFPID-5725006",
                        "CSAFPID-5725007",
                        "CSAFPID-5725008",
                        "CSAFPID-5725009",
                        "CSAFPID-5725010",
                        "CSAFPID-5725011",
                        "CSAFPID-5725012",
                        "CSAFPID-5725013",
                        "CSAFPID-5725014",
                        "CSAFPID-5725015",
                        "CSAFPID-5725016",
                        "CSAFPID-5725017",
                        "CSAFPID-5725018",
                        "CSAFPID-5725019",
                        "CSAFPID-5725020",
                        "CSAFPID-5725021",
                        "CSAFPID-5725022",
                        "CSAFPID-5725023",
                        "CSAFPID-5725024",
                        "CSAFPID-5725025",
                        "CSAFPID-5725026",
                        "CSAFPID-5725027",
                        "CSAFPID-5725028",
                        "CSAFPID-5725029",
                        "CSAFPID-5725030",
                        "CSAFPID-5725031",
                        "CSAFPID-5725032",
                        "CSAFPID-5725033",
                        "CSAFPID-5725034",
                        "CSAFPID-5725035",
                        "CSAFPID-5725036",
                        "CSAFPID-5725037",
                        "CSAFPID-5725038",
                        "CSAFPID-5725039",
                        "CSAFPID-5725040",
                        "CSAFPID-5725041",
                        "CSAFPID-5725042",
                        "CSAFPID-5725043",
                        "CSAFPID-5725044",
                        "CSAFPID-5725045",
                        "CSAFPID-5725046",
                        "CSAFPID-5725047",
                        "CSAFPID-5725048",
                        "CSAFPID-5725049",
                        "CSAFPID-5725050",
                        "CSAFPID-5725051",
                        "CSAFPID-5725052",
                        "CSAFPID-5725053",
                        "CSAFPID-5725054",
                        "CSAFPID-5725055",
                        "CSAFPID-5725056",
                        "CSAFPID-5725057",
                        "CSAFPID-5725058",
                        "CSAFPID-5725059",
                        "CSAFPID-5725060",
                        "CSAFPID-5725061",
                        "CSAFPID-5725062",
                        "CSAFPID-5725063",
                        "CSAFPID-5725064",
                        "CSAFPID-5725065",
                        "CSAFPID-5725066",
                        "CSAFPID-5725067",
                        "CSAFPID-5725068",
                        "CSAFPID-5725069",
                        "CSAFPID-5725070",
                        "CSAFPID-5725071",
                        "CSAFPID-5725072",
                        "CSAFPID-5725073",
                        "CSAFPID-5725074",
                        "CSAFPID-5725075",
                        "CSAFPID-5725076",
                        "CSAFPID-5725077",
                        "CSAFPID-5725078",
                        "CSAFPID-5725079",
                        "CSAFPID-5725080",
                        "CSAFPID-5725081",
                        "CSAFPID-5725082",
                        "CSAFPID-5725083",
                        "CSAFPID-5725084",
                        "CSAFPID-5725085",
                        "CSAFPID-5725086",
                        "CSAFPID-5725087",
                        "CSAFPID-5725088",
                        "CSAFPID-5725089",
                        "CSAFPID-5725090",
                        "CSAFPID-5725091",
                        "CSAFPID-5725092",
                        "CSAFPID-5725093",
                        "CSAFPID-5725094",
                        "CSAFPID-5725095",
                        "CSAFPID-5725096",
                        "CSAFPID-5725097",
                        "CSAFPID-5725098",
                        "CSAFPID-5725099",
                        "CSAFPID-5725100",
                        "CSAFPID-5725101",
                        "CSAFPID-5725102",
                        "CSAFPID-5725103",
                        "CSAFPID-5725104",
                        "CSAFPID-5725105",
                        "CSAFPID-5725106",
                        "CSAFPID-5725107",
                        "CSAFPID-5725108",
                        "CSAFPID-5725109",
                        "CSAFPID-5725110",
                        "CSAFPID-5725111",
                        "CSAFPID-5875603"
                    ]
                }
            ],
            "title": "CVE-2026-26205"
        }
    ]
}