GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: path-parameter canonicalization mismatch bypasses path-based RBAC DENY rules

CVSS 7.5CVE-2026-73553Container, Kubernetes & orchestrationcurated

Impact

With ignore_path_parameters_in_path_matching enabled, the router strips the semicolon suffix before route matching while the RBAC url_path matcher still evaluates the raw path. A request to /admin;x misses a DENY rule written for /admin yet still routes to the protected /admin backend. Where Envoy is the enforcement point in front of cluster tooling, model-management APIs or tenant inference routes, this turns a documented deny into no enforcement at all for unauthenticated callers. Scope is limited to deployments that have both the route option and a path-based RBAC rule.

Who can reach it

Any unauthenticated client that can send a request to the listener. No credentials needed; the attacker only appends a path parameter.

What to do

Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4 or 1.39.1 and restart the proxy - a rolling data-plane restart, no node drain. Until then, either disable ignore_path_parameters_in_path_matching on affected routes or move the authorization decision to a matcher that sees the same canonical form as the router.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.