Inconsistent interpretation of HTTP requests in envoy - CVE-2026-73548
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper handling of generic HTTP upgrades in Envoy\'s shared upstream connection pool when processing an HTTP/2 extended CONNECT request for a configured non-WebSocket upgrade type. A remote attacker can send a specially crafted extended CONNECT request containing a self-contained HTTP/1.1 request to disclose sensitive information.
Exploitation requires an HTTP/2 frontend, an HTTP/1.1 keep-alive upstream, and a configured non-WebSocket upgrade_configs entry.
Affected software
Istio
How to mitigate CVE-2026-73548
Istio - addressed in versions 1.29.7, 1.30.4