PatchSiren

Katanemo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Katanemo CVE published 2026-10-11

CVE-2026-108863

CVE-2026-108863 is a high-severity vulnerability in Katanemo Plano through version 0.4.37, allowing unauthenticated network attackers to access the Envoy admin interface on port 9901. Attackers can exploit this vulnerability to read configured LLM provider API keys in plaintext from the WASM filter configuration by requesting the /config_dump endpoint.