
CVE-2026-11752 A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenam… https://www.cve.org/CVERecord?id=CVE-2026-11752
Post summary
The passage announces a new vulnerability in armeria‑xds, describing how DataSourceStream may resolve control‑plane‑supplied filenames, but lacks any PoC, exploit, or patch information.


