Input validation error in envoy - CVE-2026-73552
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in the HTTP RBAC safe_regex header matcher when processing RFC-valid obs-text header values containing invalid UTF-8 bytes. A remote attacker can send a specially crafted request header to disclose sensitive information.
Exploitation requires an HTTP RBAC policy that applies safe_regex with negative logic and a protected operation that remains reachable when another consumer still observes the preserved header bytes.
Affected software
Istio
How to mitigate CVE-2026-73552
Istio - addressed in versions 1.29.7, 1.30.4