Improper Certificate Validation in envoy - CVE-2022-21656
Published: February 22, 2022 / Updated: August 26, 2026
Vulnerability details
The vulnerability allows a remote user to bypass X.509 subjectAltName matching and nameConstraints checks.
The vulnerability exists due to improper certificate validation in X.509 subjectAltName matching and nameConstraints processing when validating certificates. A remote user can present a specially crafted certificate to bypass X.509 subjectAltName matching and nameConstraints checks.