Database/Container, Kubernetes & orchestration
Envoy: path normalization misses ..;param segments, bypassing path-based routing and RBAC
Impact
Envoy's normalizer does not treat . and .. as dot segments when they carry a semicolon parameter, so /user/..;foo=bar/admin is not collapsed to /admin even with path normalization enabled. Envoy then makes its routing and RBAC decision on the uncollapsed path while an upstream that follows RFC 3986 resolves it to the real target. Where Envoy is the ingress or service-mesh sidecar in front of cluster services - schedulers, model endpoints, admin APIs - a remote client can reach a path that a path-based authorization policy was supposed to block. Exploitability depends on the upstream actually interpreting the segment differently, or on Envoy making a path-based decision at all; a deployment that authorizes purely on mTLS identity and not on path is not affected.
Who can reach it
Any remote client that can send an HTTP request through the affected Envoy listener. No authentication required - the point of the bug is to get past the authorization check.
What to do
Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4, or 1.39.1. For a standalone edge proxy this is a package or image update and a rolling restart of the proxy fleet; for a service mesh it means rolling the sidecar image, which restarts every injected pod - schedule it like any mesh data-plane rollout. No node reboot. As an interim mitigation, reject request paths containing ; at the edge, or move the affected authorization decisions off raw path matching.
References
Related entries
- Rancher Fleet: Helm template preprocessing reaches the network, leaking cluster metadata via DNSCVE-2026-75036 · Rancher Fleet controller (Helm template preprocessing / GitRepo bundle content)Medium
- containerd: containerd-shim abstract-socket API exposed to host-network containersCVE-2020-15257 · containerdMedium
- Kubernetes (kube-apiserver): Aggregated API server can redirect apiserver clientsCVE-2022-3172 · Kubernetes (kube-apiserver)Medium
- Docker / moby: On firewalld reload, published container ports become reachable from outside despite the intendedCVE-2025-54388 · Docker / mobyMedium
- Contrast: untrusted host can write arbitrary files into a confidential container via an unbacked VOLUME pathCVE-2025-71424 · Edgeless Systems Contrast (confidential-containers runtime, OCI VOLUME mount handling)Medium
- AWS EFS CSI Driver: crafted volumeHandle causes recursive deletion of directories on another filesystemCVE-2026-85781 · Amazon EFS CSI Driver (volume deletion, access point ownership check)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.