Envoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segment path (matrix) parameters (e.g. Apache Tomcat)
Summary
| CVE | CVE-2026-73511 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-21 21:17:09 UTC |
| Updated | 2026-10-05 14:35:20 UTC |
| Description | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolon matrix parameters from each path segment before resolving the resource. Envoy's ignore_path_parameters_in_path_matching option instead truncates at the first semicolon and still does not match per-segment backend behavior. A remote client can use a parameterized protected segment, or a parameter on an earlier segment, to make Envoy select an unprotected fallback while the backend resolves the protected resource. The relevant scope boundary is that the bypass requires both a path-based Envoy decision and a backend that strips semicolon parameters per segment. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.005540000 probability, percentile 0.451210000 (date 2026-09-22)
Problem Types: CWE-289 | CWE-436 | CWE-289 CWE-289: Authentication Bypass by Alternate Name | CWE-436 CWE-436: Interpretation Conflict
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Envoyproxy | Envoy | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Envoyproxy | Envoy | affected < 1.36.10 | Not specified |
| CNA | Envoyproxy | Envoy | affected >= 1.37.0, < 1.37.6 | Not specified |
| CNA | Envoyproxy | Envoy | affected >= 1.38.0, < 1.38.4 | Not specified |
| CNA | Envoyproxy | Envoy | affected >= 1.39.0, < 1.39.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/envoyproxy/envoy/commit/26d5 | [email protected] | github.com | Patch |
| github.com/envoyproxy/envoy/commit/b205d1f4982e14ce5693ba94ef84d37e7155e050 | [email protected] | github.com | Patch |
| github.com/envoyproxy/envoy/commit/50f7bfa48dccfee339822e9846b2b8053e07d325 | [email protected] | github.com | Patch |
| github.com/envoyproxy/envoy/releases/tag/v1.37.6 | [email protected] | github.com | Release Notes |
| github.com/envoyproxy/envoy/releases/tag/v1.39.1 | [email protected] | github.com | Release Notes |
| github.com/envoyproxy/envoy/commit/fcb663752c7055257f5dcc8b6ce6c7c905ebb1ff | [email protected] | github.com | Patch |
| github.com/envoyproxy/envoy/releases/tag/v1.36.10 | [email protected] | github.com | Release Notes |
| github.com/envoyproxy/envoy/security/advisories/GHSA-m745-gh6x-349x | [email protected] | github.com | Exploit, Vendor Advisory |
| github.com/envoyproxy/envoy/releases/tag/v1.38.4 | [email protected] | github.com | Release Notes |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.