Executive brief
Envoy, a popular open-source service proxy used to manage network traffic, is vulnerable to a request smuggling flaw when translating traffic between different web protocols (HTTP/3 to HTTP/1). An attacker can craft a specific type of request that tricks the backend server into misinterpreting where one request ends and the next begins. This allows the attacker to bypass security rules, potentially accessing restricted data or performing unauthorized actions on the backend system.
Technical details
A request smuggling vulnerability exists in Envoy's HTTP/3 to HTTP/1 translation boundary. When a downstream HTTP/3 request is received with a 'HEADERS with FIN' (headers-only close) but contains a non-zero Content-Length header, Envoy fails to reconcile the declared body size with the actual received bytes before forwarding the request. The upstream HTTP/1 codec emits the Content-Length and finalizes the request, leaving the backend origin with 'unresolved body debt.' If the backend origin replies before reading the full declared body and keeps the connection alive, it may interpret the start of a subsequent request as the body of the first, and the remainder of that subsequent request as a new, unsanitized command. This allows attackers to bypass Envoy's routing policies and authorization checks. The issue is fixed in versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
Affected products
- Envoy Proxy Envoy >= 1.35.0, < 1.35.11; >= 1.36.0, < 1.36.7; >= 1.37.0, < 1.37.3; >= 1.38.0, < 1.38.1
Timeline
- 2026-06-23: advisory: GitHub Security Advisory published by Envoy maintainers
- 2026-06-26: disclosed: CVE published to NVD