Junglewise Threat Intelligence

CVE-2026-73511: Envoy path parameter stripping bypass in access control

CVE-2026-73511 · Severity: medium · CVSS 5.3 · Published 2026-09-21

Executive brief

Envoy is a cloud-native proxy that makes routing and access control decisions based on request paths. Before the fix, Envoy's path parameter handling could be circumvented by using semicolon parameters in URL paths, allowing an attacker to bypass access controls and reach protected resources that should be denied. This affects deployments where Envoy protects backend services like Apache Tomcat that strip path parameters differently.

Technical details

Envoy truncates path parameters at the first semicolon, while servlet backends such as Tomcat strip parameters per-segment per RFC 3986. An attacker can craft a URL with parameterized path segments to cause a mismatch: Envoy's access control permits the request based on the truncated path, but the backend resolves the protected resource by stripping only segment-level parameters. The vulnerability requires both path-based access control in Envoy and a backend that implements per-segment parameter stripping, fixed by making Envoy's stripping behavior per-segment.

Affected products

  • Envoy Project Envoy before 1.36.10, 1.37.6, 1.38.4, and 1.39.1

Timeline

  • 2026-09-21: disclosed
  • 2026-08-26: patched: Fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1

References

Related threats