Junglewise Threat Intelligence

CVE-2026-73553: Envoy authorization bypass via path parameter inconsistency

CVE-2026-73553 · Severity: high · CVSS 7.5 · Published 2026-09-21

Technologies: Envoy. Vendors: Envoy.

Executive brief

Envoy is a network proxy used to route and control traffic in cloud applications. When a configuration option for ignoring path parameters is enabled, Envoy's router and authorization filter handle URLs inconsistently—allowing an attacker to append path parameters (like /admin;x) to bypass authorization policies while still reaching the protected endpoint. This enables unauthenticated users to access resources that should be blocked.

Technical details

When ignore_path_parameters_in_path_matching is enabled, the router strips path parameters (text after semicolons) during route matching, but the RBAC filter's PathMatcher and UriTemplateMatcher do not, creating an authorization bypass. An unauthenticated attacker can append path parameters to requests to evade DENY rules while the router still forwards the request to the protected backend. The vulnerability requires both the route configuration option and a path-based RBAC rule to be present, with the route matching after parameter stripping.

Affected products

  • Envoy Envoy before 1.36.10, 1.37.6, 1.38.4, and 1.39.1

Timeline

  • 2026-09-21: disclosed
  • 2026-08-26: patched: Patches released in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1

References

Related threats