Input validation error in envoy - CVE-2026-26308

 

Input validation error in envoy - CVE-2026-26308

Published: August 26, 2026


Vulnerability identifier: #VU145842
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-26308
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass RBAC header validation restrictions and disclose sensitive information.

The vulnerability exists due to improper input validation in the RBAC header validation logic when processing multiple header values concatenated into a single header entry. A remote attacker can send requests with multi-value headers to bypass RBAC header validation restrictions and disclose sensitive information.


Affected software

envoy

How to mitigate CVE-2026-26308

Install security update from vendor's website.

envoy - addressed in versions 1.34.13, 1.35.9, 1.36.5, 1.37.1

External References

Related Security Bulletins