OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-73547

HIGH · CVSS 7.5 EPSS 0.55% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Envoy's ext_authz filter is vulnerable to a denial-of-service attack due to improper handling of path-less CONNECT requests, which can lead to a crash of the Envoy process when query-parameter mutations are applied. This issue affects deployments that accept path-less CONNECT requests and utilize the ext_authz filter for authorization. Organizations using affected versions should prioritize upgrading to versions 1.36.10, 1.37.6, 1.38.4, or 1.39.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73547
Severity
HIGH
CVSS
7.5
EPSS
0.55%

Original NVD Description

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes request_headers_->Path() return null, and Filter::onComplete dereferences that pointer while parsing the query string. An unauthenticated downstream client can crash the Envoy process when the filter and authorization response use query-parameter mutation. The relevant scope boundary is that the deployment must accept path-less CONNECT and configure ext_authz query-parameter mutation. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)