GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: null :path dereference in ext_authz query-parameter mutation crashes the proxy

CVSS 7.5CVE-2026-73547Container, Kubernetes & orchestrationcurated

Impact

Envoy's ext_authz filter assumes a request carries a :path pseudoheader when it applies query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes Path() return null and Filter::onComplete dereferences it while parsing the query string, killing the Envoy process. Availability only - no data disclosure - but an unauthenticated client can repeat it at will, so any ingress or mesh sidecar in that configuration becomes a one-request kill switch. Where Envoy fronts inference endpoints or sits as the mesh data plane in front of GPU workloads, a crash loop takes the serving path down even though the GPU nodes themselves are healthy.

Who can reach it

Any unauthenticated downstream client that can send a path-less CONNECT request to a listener where the ext_authz filter is enabled and the authorization response performs query-parameter mutation. Deployments that do not accept path-less CONNECT, or do not use query-parameter mutation, are outside the described scope.

What to do

Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4, or 1.39.1. Cost depends on where Envoy runs: a restart of the ingress or gateway fleet, or a sidecar image roll across the mesh, which means a rolling restart of every injected pod. As an interim measure the two preconditions named in the advisory are both configuration - drop path-less CONNECT at the edge, or remove query-parameter mutation from the ext_authz response - either of which can be applied without a binary upgrade.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.