{"id":"GHSA-hgw6-8c77-v4gq","summary":"Armeria: External Control of File Name or Path in xDS SDS DataSource","details":"## External Control of File Name or Path in xDS SDS DataSource\n\n### Summary\n\n`DataSourceStream` in the `:xds` module resolves control-plane-supplied `filename` and `environment_variable` fields from SDS Secret resources without any allow-list or base-directory confinement. A semi-trusted or compromised xDS control plane (or an attacker who can MITM SDS responses) can read arbitrary local files and environment variables on the xDS client host.\n\n**Affected component:** `xds/src/main/java/com/linecorp/armeria/xds/DataSourceStream.java`\n**Introduced in:** Armeria 1.38.0 (commit `b199560b10`, \"Add support for SDS\", #6597)\n**Affected versions:** 1.38.0, 1.39.0\n\n### Impact\n\nA semi-trusted or compromised xDS control plane (or an attacker who can inject/MITM SDS responses) can:\n\n- **Read arbitrary files** on the xDS client host — TLS private keys, `/etc/passwd`, mounted Kubernetes service-account tokens, cloud credential files, etc.\n- **Read arbitrary environment variables** — `AWS_SECRET_ACCESS_KEY`, CI tokens, database credentials, etc.\n\nThe read bytes are consumed as TLS key/cert/CA material. Combined with CWE-295 (silent disabling of upstream TLS peer verification), the exfiltrated secret can be presented to an attacker-chosen upstream, enabling data exfiltration. This is a confused-deputy / information-disclosure primitive driven entirely by control-plane-supplied configuration.\n\n**Severity:** High — arbitrary host-level file and environment variable read via control-plane-pushed configuration.\n\n### Patches\n\n1.40.0\n\nThe fix should:\n\n1. **Confine `filename` resolution** to an operator-configured allow-list of base directories. After normalization, reject any path that escapes the allow-listed root.\n2. **Gate `environment_variable`** behind an explicit operator allow-list of permitted variable names.\n3. **Default to denying** both `filename` and `environment_variable` DataSources for control-plane-delivered (SDS) secrets unless explicitly enabled by the operator. This is stricter than upstream Envoy but appropriate when the control plane is not fully trusted.\n4. **Document the trust model** clearly so operators understand that enabling file/env DataSources grants the control plane host-level read capability.\n\n### Workarounds\n\n- Ensure the xDS control plane channel is authenticated and encrypted (mTLS) to prevent MITM injection of malicious SDS responses.\n- Run the xDS client with minimal filesystem permissions and a restricted environment to limit the blast radius of arbitrary reads.\n- If SDS file-based secrets are not needed, consider using inline `DataSource` bytes only (delivered over the SDS stream itself) and auditing control-plane configurations to ensure no `filename` or `environment_variable` DataSources are present.","aliases":["CVE-2026-11752"],"modified":"2026-07-15T22:00:52.618831495Z","published":"2026-06-18T17:22:17Z","database_specific":{"nvd_published_at":"2026-06-19T06:17:01Z","cwe_ids":["CWE-73"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-18T17:22:17Z"},"references":[{"type":"WEB","url":"https://github.com/line/armeria/security/advisories/GHSA-hgw6-8c77-v4gq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11752"},{"type":"PACKAGE","url":"https://github.com/line/armeria"},{"type":"WEB","url":"https://github.com/line/armeria/security/advisories/xds/src/main/java/com/linecorp/armeria/xds/DataSourceStream.java"}],"affected":[{"package":{"name":"com.linecorp.armeria:armeria-xds","ecosystem":"Maven","purl":"pkg:maven/com.linecorp.armeria/armeria-xds"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.40.0"}]}],"versions":["1.27.0","1.27.1","1.27.2","1.27.3","1.28.0","1.28.1","1.28.2","1.28.3","1.28.4","1.29.0","1.29.1","1.29.2","1.29.3","1.29.4","1.29.5","1.30.0","1.30.1","1.30.2","1.30.3","1.30.4","1.30.5","1.31.0","1.31.1","1.31.2","1.31.3","1.32.0","1.32.1","1.32.2","1.32.3","1.32.4","1.32.5","1.32.6","1.33.0","1.33.1","1.33.2","1.33.3","1.33.4","1.34.0","1.34.1","1.34.2","1.35.0","1.36.0","1.37.0","1.38.0","1.38.1","1.39.0","1.39.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-hgw6-8c77-v4gq/GHSA-hgw6-8c77-v4gq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}