Database/Container, Kubernetes & orchestration
Envoy: semicolon path parameters make routing pick an unprotected route for a protected resource
Impact
Envoy matches the raw request path, while servlet backends such as Tomcat strip semicolon matrix parameters per path segment before resolving a resource. The ignore_path_parameters_in_path_matching option truncates at the first semicolon instead, which still does not reproduce the backend's per-segment behaviour. A remote client can attach a parameter to a protected segment, or to an earlier segment, so Envoy selects an unprotected fallback route while the backend serves the protected resource - an authorization bypass for any policy expressed as a path match. This matters wherever Envoy is the ingress or mesh sidecar in front of cluster services: a path-based allow rule in front of an internal API or model endpoint can be stepped around without credentials.
Who can reach it
Any remote client that can send HTTP requests to the Envoy listener. No authentication needed. Exposure requires both a path-based Envoy authorization decision and a backend that strips semicolon parameters per segment.
What to do
Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4, or 1.39.1 and restart or hot-restart the proxies; for sidecars this is a rolling pod restart, for ingress a rolling replace behind the load balancer - no node drain. If an upgrade has to wait, stop relying on raw-path matching for authorization: reject requests containing ; at the edge, or enforce authorization in the backend.
References
Related entries
- Envoy: scoped IPv6 address reconstruction aborts the proxy process in ORIGINAL_DST and QUIC pathsCVE-2026-73549 · Envoy Utility::copyInternetAddressAndPort and QUIC client-address handling (scoped IPv6 addresses)Medium
- Envoy: path normalization misses ..;param segments, bypassing path-based routing and RBACCVE-2026-73551 · Envoy (URL path normalization, dot segments with semicolon parameters)Medium
- Rancher Fleet: Helm template preprocessing reaches the network, leaking cluster metadata via DNSCVE-2026-75036 · Rancher Fleet controller (Helm template preprocessing / GitRepo bundle content)Medium
- containerd: containerd-shim abstract-socket API exposed to host-network containersCVE-2020-15257 · containerdMedium
- Kubernetes (kube-apiserver): Aggregated API server can redirect apiserver clientsCVE-2022-3172 · Kubernetes (kube-apiserver)Medium
- Docker / moby: On firewalld reload, published container ports become reachable from outside despite the intendedCVE-2025-54388 · Docker / mobyMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.