#VU119109 Incorrect Regular Expression in envoy - CVE-2025-46821
Published: December 3, 2025
envoy
Cloud Native Computing Foundation
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient input validation within the template matcher that incorrectly excludes the "*" character from a set of valid characters in the URI path. A remote attacker can bypass RBAC rules when configured using the uri_template permissions.