Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values
Summary
| CVE | CVE-2026-73552 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-21 20:17:28 UTC |
| Updated | 2026-09-22 16:17:53 UTC |
| Description | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semantics. A downstream client can preserve a prohibited marker and add an unrelated obs-text octet, causing RE2::FullMatch to return false and a negative RBAC policy to treat the invalid subject as an ordinary no-match. A byte-oriented route matcher can still observe the marker, allowing the request to reach a route intended to be denied. The relevant scope boundary is that plain positive ALLOW regexes normally fail closed, and exact, prefix, suffix, and contains matchers are not shown to have this subject-domain failure. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-20 | CWE-20 CWE-20: Improper Input Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Envoyproxy | Envoy | affected < 1.36.10 | Not specified |
| CNA | Envoyproxy | Envoy | affected >= 1.37.0, < 1.37.6 | Not specified |
| CNA | Envoyproxy | Envoy | affected >= 1.38.0, < 1.38.4 | Not specified |
| CNA | Envoyproxy | Envoy | affected >= 1.39.0, < 1.39.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/envoyproxy/envoy/commit/7d1dee5dda66434d84437cc5c85153aa03955e26 | [email protected] | github.com | |
| github.com/envoyproxy/envoy/releases/tag/v1.37.6 | [email protected] | github.com | |
| github.com/envoyproxy/envoy/releases/tag/v1.39.1 | [email protected] | github.com | |
| github.com/envoyproxy/envoy/releases/tag/v1.36.10 | [email protected] | github.com | |
| github.com/envoyproxy/envoy/commit/c2b9a19dc081f03be6a9b4ca932673e5e7a33d18 | [email protected] | github.com | |
| github.com/envoyproxy/envoy/security/advisories/GHSA-23xh-2qxr-3xv8 | [email protected] | github.com | |
| github.com/envoyproxy/envoy/commit/f3726765f3a12ddc76dcb52c0b79bec3d95ced1c | [email protected] | github.com | |
| github.com/envoyproxy/envoy/commit/5650cb9770d4420ec2bcbed8b90be06f564ecc07 | [email protected] | github.com | |
| github.com/envoyproxy/envoy/releases/tag/v1.38.4 | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.