Database/Container, Kubernetes & orchestration
Envoy: crash when remote JWKS fetch fails with multiple JWT tokens and allow_missing_or_failed
Impact
A re-entry bug in JwksFetcherImpl crashes Envoy when the JWT filter is configured with remote JWKS fetching and allow_missing_or_failed, a request carries multiple JWT tokens, and the JWKS fetch fails. The crash takes down the proxy process, so every route behind that Envoy - inference endpoints, internal APIs, mesh sidecar traffic - drops with it. It is reachable by sending an ordinary request at a moment when the JWKS endpoint is unreachable, which an attacker can often arrange or simply wait for. Availability only; no disclosure or code execution. Deployments that do not use remote JWKS fetching with allow_missing_or_failed are not affected.
Who can reach it
Anyone who can send a request through an affected Envoy listener, with two or more JWT tokens in the headers, while the remote JWKS fetch fails. The CVSS vector assumes low privileges; no valid token is required since the failure path is the one that crashes.
What to do
Upgrade to a release above 1.33.12, 1.34.10, 1.35.6, or 1.36.2 on your branch, then restart or roll the Envoy fleet - a rolling restart of gateway pods and sidecars, no node action needed. If you cannot upgrade immediately, either disable allow_missing_or_failed on the JWT filter or switch to a local JWKS instead of remote fetching to remove the affected path.
References
Related entries
- secrets-store-sync-controller: Service account tokens disclosed in controller logsCVE-2025-7445 · secrets-store-sync-controllerMedium
- KubeVirt: virt-handler notify server derives VMI identity from the request body without validating the connectionCVE-2026-13208 · KubeVirtMedium
- ingress-nginx: Admission controller denial of serviceCVE-2026-24514 · ingress-nginxMedium
- CSI Driver NFS: Path traversal via `subDir` lets a tenant delete unintended directories on the shared NFS serverCVE-2026-3864 · CSI Driver NFSMedium
- CSI Driver SMB: Same `subDir` path traversal against a shared SMB serverCVE-2026-3865 · CSI Driver SMBMedium
- Contour: fallback certificate with JWT providers lets SNI-less requests skip JWT verificationCVE-2026-50149 · Projectcontour Contour ingress controller (HTTPProxy fallback certificate + jwtProviders)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.