Database/Container, Kubernetes & orchestration
Envoy proxy (ext_authz filter): When Envoy's ext_authz filter is configured with failure_mode_allow set to true
Impact
When Envoy's ext_authz filter is configured with failure_mode_allow set to true, a downstream client can force an invalid gRPC request that circumvents the external-authorization check entirely — meaning traffic that should have been checked against an auth service (a common pattern for gating access to inference or cluster-management endpoints) sails through unauthenticated.
Who can reach it
Remote — a downstream client crafts a malformed gRPC request against an Envoy instance where ext_authz is set to fail open.
What to do
Software upgrade to Envoy 1.29.1, 1.28.1, 1.27.3, 1.26.7, or later. No config workaround exists (the vendor advisory states none), so this is a binary/image upgrade and restart across every Envoy instance doing ext_authz-based access control in the cluster ingress path — a rolling restart avoids a hard outage if you run multiple replicas.
References
Related entries
- Contrast: flawed CopyFile policy check lets the untrusted host write arbitrary files into the confidential guestCVE-2026-100838 · Contrast confidential-computing runtime for Kubernetes (generated Kata agent CopyFile policy)High
- Harbor (harbor-helm, default core.secretName JWT signing key): SUPPLY CHAIN, UNAUTHENTICATED REGISTRY ACCESS: HarborNCVD-2023-011-harbor-harbor-helm-default-core · Harbor (harbor-helm, default core.secretName JWT signing key)High
- Helm: The `lookup` template function discloses in-cluster resources, including Secrets, to a chart authorCVE-2020-11013 · HelmHigh
- runc: Container filesystem breakout via directory traversal in mount handlingCVE-2021-30465 · runcHigh
- Argo CD: Authorization bypass lets an Application be synced to a destination it is not permitted to reachCVE-2023-22736 · Argo CDHigh
- KubeVirt CDI: PVCs can be cloned from unauthorized namespaces via DataImportCronCVE-2025-14459 · KubeVirt CDIHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.