Junglewise Threat Intelligence

CVE-2026-47778: Envoy improper certificate validation via NUL byte truncation in DNS SAN

CVE-2026-47778 · Severity: medium · CVSS 4.4 · Published 2026-06-26

Technologies: Envoy Proxy Envoy. Vendors: Envoy Proxy.

Executive brief

Envoy is a popular open-source tool used to manage and secure network traffic between cloud applications. A flaw in how it checks security certificates allows an attacker to impersonate a trusted service by using a specially crafted certificate containing a hidden 'null' character. If successful, an attacker could intercept sensitive data or bypass security controls intended to verify the identity of backend servers.

Technical details

A vulnerability exists in Envoy's DefaultCertValidator::verifySubjectAltName due to improper handling of NUL bytes in DNS Subject Alternative Names (SANs). When extracting a DNS SAN, the string is cast to a C-style string using .c_str() before being passed to Utility::dnsNameMatch(). Because the underlying conversion to absl::string_view relies on strlen(), the string is prematurely truncated at the NUL byte. An attacker with a certificate containing a SAN like 'target.com\0.attacker.com' can successfully match against a required 'target.com' configuration. This allows an attacker who can obtain such a certificate from a trusted CA to perform Man-in-the-Middle (MITM) attacks against upstream routing. The issue is fixed by removing the .c_str() cast to ensure the full string length is preserved during comparison.

Affected products

  • Envoy Proxy Envoy < 1.35.11, 1.36.0 to < 1.36.7, 1.37.0 to < 1.37.3, 1.38.0 to < 1.38.1

Timeline

  • 2026-06-23: advisory: GitHub advisory GHSA-f8x4-rw5x-f3r7 published
  • 2026-06-26: disclosed: CVE-2026-47778 published to NVD

References

Related threats