NULL pointer dereference in envoy - #VU153339
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in KeySources::Source::removeKey in the api_key_auth HTTP filter when stripping a query key source from a request without a :path header. A remote user can send a path-less CONNECT request with a valid API key to cause a denial of service.
Exploitation requires forwarding.hide_credentials to be enabled and at least two key sources to be configured, including a query key source.