7.5

CVE-2026-73552

Exploit

Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semantics. A downstream client can preserve a prohibited marker and add an unrelated obs-text octet, causing RE2::FullMatch to return false and a negative RBAC policy to treat the invalid subject as an ordinary no-match. A byte-oriented route matcher can still observe the marker, allowing the request to reach a route intended to be denied. The relevant scope boundary is that plain positive ALLOW regexes normally fail closed, and exact, prefix, suffix, and contains matchers are not shown to have this subject-domain failure. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Envoyproxy ≫ Envoy Version < 1.36.10
Envoyproxy ≫ Envoy Version >= 1.37.0 < 1.37.6
Envoyproxy ≫ Envoy Version >= 1.38.0 < 1.38.4
Envoyproxy ≫ Envoy Version >= 1.39.0 < 1.39.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.504
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://github.com/envoyproxy/envoy/releases/tag/v1.36.10
Release Notes
https://github.com/envoyproxy/envoy/releases/tag/v1.37.6
Release Notes
https://github.com/envoyproxy/envoy/releases/tag/v1.38.4
Release Notes
https://github.com/envoyproxy/envoy/releases/tag/v1.39.1
Release Notes
https://github.com/envoyproxy/envoy/security/advisories/GHSA-23xh-2qxr-3xv8
Vendor Advisory
Exploit
https://github.com/envoyproxy/envoy/commit/5650cb9770d4420ec2bcbed8b90be06f564ecc07
Patch
https://github.com/envoyproxy/envoy/commit/7d1dee5dda66434d84437cc5c85153aa03955e26
Patch
https://github.com/envoyproxy/envoy/commit/c2b9a19dc081f03be6a9b4ca932673e5e7a33d18
Patch
https://github.com/envoyproxy/envoy/commit/f3726765f3a12ddc76dcb52c0b79bec3d95ced1c
Patch