Executive brief
Envoy, an open source edge and service proxy for cloud-native applications, fails to properly canonicalize URL paths when they contain dot and dotdot segments with semicolon parameters. An attacker can craft malicious requests like /user/..;foo=bar/admin that bypass path-based security controls, potentially allowing unauthorized access to restricted endpoints if the upstream server interprets the path differently than Envoy's routing engine.
Technical details
The vulnerability occurs in Envoy's URL path normalization logic, which does not strip semicolon parameters from dot (..) and dotdot (..) path segments before canonicalization. This results in a path confusion flaw where Envoy applies routing or role-based access control (RBAC) decisions to an uncollapsed path, while an upstream server following RFC 3986 collapses the path differently. The attack requires path normalization to be enabled and depends on downstream/upstream path interpretation mismatches.
Affected products
- Envoy Envoy before 1.36.10, before 1.37.6, before 1.38.4, before 1.39.1
Timeline
- 2026-09-21: disclosed
- 2026-08-26: patched: Fix committed to repository; releases 1.36.10, 1.37.6, 1.38.4, 1.39.1