Use of Non-Canonical URL Paths for Authorization Decisions in envoy - CVE-2026-73551
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass path-based authorization or routing policies.
The vulnerability exists due to use of non-canonical url paths for authorization decisions in URL path normalization and path matching when handling HTTP requests with path segments containing dot or dotdot parameters. A remote attacker can send a specially crafted request to bypass path-based authorization or routing policies.
The issue can also cause path confusion between Envoy and an upstream service.
Affected software
Istio
How to mitigate CVE-2026-73551
Istio - addressed in versions 1.29.7, 1.30.4