GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: stored XSS through unescaped dynamic statistic names on the admin stats page

CVSS 7.4CVE-2026-73546Container, Kubernetes & orchestrationcurated

Impact

StatsHtmlRender sanitizes statistic values but emits statistic names without HTML encoding. A data-plane filter such as grpc_stats with stats_for_all_methods enabled folds attacker-controlled path segments into cached dynamic stat names, so a remote client can persist script into the admin interface. When an operator later opens /stats?format=html in a browser, that script runs with the admin origin and can issue privileged same-origin requests to the admin API - which can reconfigure or shut down the proxy. This matters where an operator or dashboard reaches the Envoy admin port from a browser; an admin interface bound to localhost and never browsed is not exposed.

Who can reach it

Remote unauthenticated client to shape the stat name, then an operator viewing the HTML stats page in a browser. Requires the admin interface to be browser-accessible and a component that persists attacker-influenced text in stat names.

What to do

Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4 or 1.39.1 and restart the proxy. Meanwhile disable stats_for_all_methods on grpc_stats, keep the admin interface off any browser-reachable network, and read stats via the JSON or Prometheus formats rather than HTML.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.