Executive brief
Envoy is a widely-used network proxy that enforces access control policies on HTTP traffic. The vulnerability allows a malicious downstream client to bypass HTTP role-based access control (RBAC) policies by crafting specially-formed header bytes that exploit a regex evaluation flaw. An attacker can reach routes that should be denied by the RBAC policy, potentially leading to unauthorized access to protected services.
Technical details
The vulnerability exists in Envoy's HTTP RBAC implementation, which evaluates safe_regex policy expressions using RE2's UTF-8 subject semantics even though HTTP headers are Latin1-encoded bytes. An attacker can preserve a prohibited marker in the header and append an invalid obs-text octet, causing RE2::FullMatch to return false for negative RBAC policies while a byte-oriented route matcher still observes the marker. The fix switches safe_regex charset mode from UTF-8 to Latin1 to properly handle HTTP header bytes.
Affected products
- Envoy Envoy before 1.36.10, 1.37.0-1.37.5, 1.38.0-1.38.3, 1.39.0
Timeline
- 2026-09-21: disclosed
- 2026-08-26: patched: Fix committed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1