Bug 2512095 (CVE-2026-73511)
| Summary: | CVE-2026-73511 envoy: envoy: path matching bypass via per-segment parameters not stripped by router | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | kaycoth, security-response-team |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Envoy. A remote attacker can exploit this vulnerability by submitting an HTTP request containing per-segment path parameters separated by semicolons. Due to differences in how Envoy and backend servers process these parameters, path matching rules can become misaligned, potentially allowing an attacker to bypass path-based access controls or authentication mechanisms.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Deadline: | 2026-08-26 | ||
|
Description
OSIDB Bzimport
2026-08-06 15:01:46 UTC
|