GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: semicolon path parameters make routing pick an unprotected route for a protected resource

CVSS 5.3CVE-2026-73511Container, Kubernetes & orchestrationcurated

Impact

Envoy matches the raw request path, while servlet backends such as Tomcat strip semicolon matrix parameters per path segment before resolving a resource. The ignore_path_parameters_in_path_matching option truncates at the first semicolon instead, which still does not reproduce the backend's per-segment behaviour. A remote client can attach a parameter to a protected segment, or to an earlier segment, so Envoy selects an unprotected fallback route while the backend serves the protected resource - an authorization bypass for any policy expressed as a path match. This matters wherever Envoy is the ingress or mesh sidecar in front of cluster services: a path-based allow rule in front of an internal API or model endpoint can be stepped around without credentials.

Who can reach it

Any remote client that can send HTTP requests to the Envoy listener. No authentication needed. Exposure requires both a path-based Envoy authorization decision and a backend that strips semicolon parameters per segment.

What to do

Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4, or 1.39.1 and restart or hot-restart the proxies; for sidecars this is a rolling pod restart, for ingress a rolling replace behind the load balancer - no node drain. If an upgrade has to wait, stop relying on raw-path matching for authorization: reject requests containing ; at the edge, or enforce authorization in the backend.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.