7.5

CVE-2026-73547

Exploit

Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes request_headers_->Path() return null, and Filter::onComplete dereferences that pointer while parsing the query string. An unauthenticated downstream client can crash the Envoy process when the filter and authorization response use query-parameter mutation. The relevant scope boundary is that the deployment must accept path-less CONNECT and configure ext_authz query-parameter mutation. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Envoyproxy ≫ Envoy Version < 1.36.10
Envoyproxy ≫ Envoy Version >= 1.37.0 < 1.37.6
Envoyproxy ≫ Envoy Version >= 1.38.0 < 1.38.4
Envoyproxy ≫ Envoy Version >= 1.39.0 < 1.39.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.83% 0.559
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://github.com/envoyproxy/envoy/releases/tag/v1.36.10
Release Notes
https://github.com/envoyproxy/envoy/releases/tag/v1.37.6
Release Notes
https://github.com/envoyproxy/envoy/releases/tag/v1.38.4
Release Notes
https://github.com/envoyproxy/envoy/releases/tag/v1.39.1
Release Notes
https://github.com/envoyproxy/envoy/security/advisories/GHSA-87ph-jqwm-pg6r
Vendor Advisory
Exploit
https://github.com/envoyproxy/envoy/commit/064af2e61d0d1c421490d9e3e6e643c5d117ffe4
Patch
https://github.com/envoyproxy/envoy/commit/5f3b8e9b2b8a787a63202d35bb38820f3e9271fe
Patch
https://github.com/envoyproxy/envoy/commit/838f8ffd9d7b5217682a22ee33470d4c7afb7e98
Patch
https://github.com/envoyproxy/envoy/commit/c3170d7c747e51bb8254378ea89afc03d3e71929
Patch