Database/Container, Kubernetes & orchestration
Envoy: request smuggling via non-WebSocket HTTP upgrade leaks responses to other clients
Impact
An unauthenticated HTTP/2 client can embed a complete HTTP/1.1 request inside extended CONNECT data for a configured non-WebSocket upgrade. Envoy writes that data unframed to a keep-alive HTTP/1.1 upstream and returns the socket to the shared pool with the smuggled response still queued, so the next downstream client on that pool gets the attacker's response. On a GPU cluster where Envoy fronts inference endpoints or sits in the service mesh, that means cross-tenant response leakage: one tenant's prompt or model output can be delivered to another tenant's request. WebSocket upgrades, plain CONNECT, disabled upstream keep-alive, per-downstream pools, and max_requests_per_connection=1 are outside the demonstrated path.
Who can reach it
Any unauthenticated client that can reach a listener with a non-WebSocket HTTP upgrade configured and a keep-alive HTTP/1.1 upstream behind it. No credentials needed.
What to do
Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4 or 1.39.1 and restart the proxy; a rolling restart of the mesh data plane or gateway fleet is enough, no node drain. As an interim mitigation, remove non-WebSocket upgrade_configs, or set max_requests_per_connection to 1 / disable upstream keep-alive on the affected clusters.
References
Related entries
- Envoy: duplicate Host headers escape request header limits and let a client OOM-kill the proxyCVE-2026-73550 · Envoy (HTTP/2 duplicate Host header handling, header-limit accounting)High
- Envoy: non-UTF-8 header byte makes safe_regex RBAC rules read as no-match, bypassing DENYCVE-2026-73552 · Envoy (HTTP RBAC safe_regex matcher, RE2 UTF-8 subject semantics)High
- Envoy: path-parameter canonicalization mismatch bypasses path-based RBAC DENY rulesCVE-2026-73553 · Envoy (RBAC url_path matcher vs ignore_path_parameters_in_path_matching)High
- Skipper: OPA body policies authorize oversized requests because truncated_body is derived from Content-LengthCVE-2026-86043 · Skipper HTTP router (opaAuthorizeRequestWithBody / OPA body truncation)High
- BuildKit: image can advertise another image's DiffIDs, poisoning shared build cacheCVE-2026-93318 · BuildKit (layer DiffID cache and snapshot identity validation)High
- Envoy: Type-confusion in default certificate validationCVE-2022-21656 · EnvoyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.