Input validation error in envoy - CVE-2026-26308
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass RBAC header validation restrictions and disclose sensitive information.
The vulnerability exists due to improper input validation in the RBAC header validation logic when processing multiple header values concatenated into a single header entry. A remote attacker can send requests with multi-value headers to bypass RBAC header validation restrictions and disclose sensitive information.