Fedora Account System
Red Hat Associate
Red Hat Customer
safe_regex matching treated accepted non-UTF-8 HTTP header bytes as an ordinary non-match. In RBAC policies using negative matching logic, this could cause a rule to fail open and allow access to a protected resource. The fix uses the Latin-1 character set when applying regular expressions to byte-oriented HTTP values. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5) Embargoed until 2026-08-26 13:00 GMT per Envoy upstream disclosure. PSIRTSUPT-21132.