These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,171 reserved CVEs with public mentions, ranked by all-time mention count.
Page 25 of 47
CVE-2026-53713 is an authentication bypass and path traversal vulnerability in Envoy Gateway's EnvoyExtensionPolicy Lua handling. Improper input validation in the logic intended to protect critical file-access paths allows an attacker who can submit Lua code through an EnvoyExtensionPolicy to evade traversal protections by using redundant path separators. By bypassing these checks, the attacker can cause the gateway controller pod to read arbitrary files from its filesystem, including sensitive operating system files, Kubernetes service account material, TLS certificates, and process environment data. The issue stems from insufficient normalization and validation of path input before enforcing traversal restrictions.
CVE-2026-53713First seen Jun 12, 2026
First seen Jul 17, 2026
First seen Jul 17, 2026
First seen Jul 17, 2026
First seen Jul 17, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026
First seen Jul 16, 2026