GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: non-UTF-8 header byte makes safe_regex RBAC rules read as no-match, bypassing DENY

CVSS 7.5CVE-2026-73552Container, Kubernetes & orchestrationcurated

Impact

Envoy's HTTP RBAC filter accepts RFC-valid opaque header bytes but evaluates safe_regex values under RE2's UTF-8 subject semantics. A client can keep a prohibited marker in a header and add an unrelated obs-text octet, so RE2::FullMatch returns false and a negative RBAC policy treats the invalid subject as an ordinary no-match - while a byte-oriented route matcher still sees the marker and routes the request to a backend that was meant to be denied. For operators using regex DENY rules to fence off internal or per-tenant routes on a shared gateway, the fence silently stops applying. Plain positive ALLOW regexes normally fail closed, and exact/prefix/suffix/contains matchers were not shown to be affected.

Who can reach it

Any unauthenticated downstream client able to set the header the regex policy inspects.

What to do

Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4 or 1.39.1 and restart the proxy (rolling restart of the gateway or sidecar fleet). Interim: express the rule as an ALLOW-list, or replace safe_regex DENY conditions with exact/prefix/suffix/contains matchers.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.