Interpretation Conflict in envoy - CVE-2026-73511
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication or authorization checks.
The vulnerability exists due to interpretation conflict in Envoy path matching when processing request paths containing per-segment path parameters with a backend that strips those parameters per segment. A remote attacker can send a specially crafted request path to bypass authentication or authorization checks.
Exploitation requires a deployment in which Envoy makes path-based security decisions and the backend strips matrix parameters from each path segment.
Affected software
Istio
How to mitigate CVE-2026-73511
Istio - addressed in versions 1.29.7, 1.30.4