Executive brief
Envoy is a popular open-source tool used to manage and secure network traffic between cloud applications. A flaw in how it checks security certificates allows an attacker to impersonate a trusted service by using a specially crafted certificate containing a hidden 'null' character. If successful, an attacker could intercept sensitive data or bypass security controls intended to verify the identity of backend servers.
Technical details
A vulnerability exists in Envoy's DefaultCertValidator::verifySubjectAltName due to improper handling of NUL bytes in DNS Subject Alternative Names (SANs). When extracting a DNS SAN, the string is cast to a C-style string using .c_str() before being passed to Utility::dnsNameMatch(). Because the underlying conversion to absl::string_view relies on strlen(), the string is prematurely truncated at the NUL byte. An attacker with a certificate containing a SAN like 'target.com\0.attacker.com' can successfully match against a required 'target.com' configuration. This allows an attacker who can obtain such a certificate from a trusted CA to perform Man-in-the-Middle (MITM) attacks against upstream routing. The issue is fixed by removing the .c_str() cast to ensure the full string length is preserved during comparison.
Affected products
- Envoy Proxy Envoy < 1.35.11, 1.36.0 to < 1.36.7, 1.37.0 to < 1.37.3, 1.38.0 to < 1.38.1
Timeline
- 2026-06-23: advisory: GitHub advisory GHSA-f8x4-rw5x-f3r7 published
- 2026-06-26: disclosed: CVE-2026-47778 published to NVD