PT-2026-24377 · Envoy · Envoy
Dor Konis
·
Publicado
2026-03-10
·
Atualizado
2026-03-12
·
CVE-2026-26308
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Envoy versions prior to 1.37.1
Envoy versions prior to 1.36.5
Envoy versions prior to 1.35.8
Envoy versions prior to 1.34.13
Description
Envoy is a high-performance edge/middle/service proxy. The Envoy RBAC (Role-Based Access Control) filter has a logic issue in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This allows attackers to bypass RBAC policies—specifically "Deny" rules—by sending duplicate headers, obscuring the malicious value from exact-match mechanisms. The vulnerability affects the validation of headers used in RBAC policies.
Recommendations
Update to version 1.37.1.
Update to version 1.36.5.
Update to version 1.35.8.
Update to version 1.34.13.
Enable
rbac match headers individually.Exploit
Correção
Incorrect Authorization
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Envoy