Database/Container, Kubernetes & orchestration
Envoy: null :path dereference in ext_authz query-parameter mutation crashes the proxy
Impact
Envoy's ext_authz filter assumes a request carries a :path pseudoheader when it applies query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes Path() return null and Filter::onComplete dereferences it while parsing the query string, killing the Envoy process. Availability only - no data disclosure - but an unauthenticated client can repeat it at will, so any ingress or mesh sidecar in that configuration becomes a one-request kill switch. Where Envoy fronts inference endpoints or sits as the mesh data plane in front of GPU workloads, a crash loop takes the serving path down even though the GPU nodes themselves are healthy.
Who can reach it
Any unauthenticated downstream client that can send a path-less CONNECT request to a listener where the ext_authz filter is enabled and the authorization response performs query-parameter mutation. Deployments that do not accept path-less CONNECT, or do not use query-parameter mutation, are outside the described scope.
What to do
Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4, or 1.39.1. Cost depends on where Envoy runs: a restart of the ingress or gateway fleet, or a sidecar image roll across the mesh, which means a rolling restart of every injected pod. As an interim measure the two preconditions named in the advisory are both configuration - drop path-less CONNECT at the edge, or remove query-parameter mutation from the ext_authz response - either of which can be applied without a binary upgrade.
References
Related entries
- Envoy: request smuggling via non-WebSocket HTTP upgrade leaks responses to other clientsCVE-2026-73548 · Envoy (HTTP/1.1 upstream connection pool, non-WebSocket upgrade path)High
- Envoy: duplicate Host headers escape request header limits and let a client OOM-kill the proxyCVE-2026-73550 · Envoy (HTTP/2 duplicate Host header handling, header-limit accounting)High
- Envoy: non-UTF-8 header byte makes safe_regex RBAC rules read as no-match, bypassing DENYCVE-2026-73552 · Envoy (HTTP RBAC safe_regex matcher, RE2 UTF-8 subject semantics)High
- Envoy: path-parameter canonicalization mismatch bypasses path-based RBAC DENY rulesCVE-2026-73553 · Envoy (RBAC url_path matcher vs ignore_path_parameters_in_path_matching)High
- Skipper: OPA body policies authorize oversized requests because truncated_body is derived from Content-LengthCVE-2026-86043 · Skipper HTTP router (opaAuthorizeRequestWithBody / OPA body truncation)High
- BuildKit: image can advertise another image's DiffIDs, poisoning shared build cacheCVE-2026-93318 · BuildKit (layer DiffID cache and snapshot identity validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.