Database/Container, Kubernetes & orchestration
Envoy: path-parameter canonicalization mismatch bypasses path-based RBAC DENY rules
Impact
With ignore_path_parameters_in_path_matching enabled, the router strips the semicolon suffix before route matching while the RBAC url_path matcher still evaluates the raw path. A request to /admin;x misses a DENY rule written for /admin yet still routes to the protected /admin backend. Where Envoy is the enforcement point in front of cluster tooling, model-management APIs or tenant inference routes, this turns a documented deny into no enforcement at all for unauthenticated callers. Scope is limited to deployments that have both the route option and a path-based RBAC rule.
Who can reach it
Any unauthenticated client that can send a request to the listener. No credentials needed; the attacker only appends a path parameter.
What to do
Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4 or 1.39.1 and restart the proxy - a rolling data-plane restart, no node drain. Until then, either disable ignore_path_parameters_in_path_matching on affected routes or move the authorization decision to a matcher that sees the same canonical form as the router.
References
Related entries
- Skipper: OPA body policies authorize oversized requests because truncated_body is derived from Content-LengthCVE-2026-86043 · Skipper HTTP router (opaAuthorizeRequestWithBody / OPA body truncation)High
- BuildKit: image can advertise another image's DiffIDs, poisoning shared build cacheCVE-2026-93318 · BuildKit (layer DiffID cache and snapshot identity validation)High
- Envoy: Type-confusion in default certificate validationCVE-2022-21656 · EnvoyHigh
- Rancher: Missing authorization allows an authenticated user to create a shell pod with kubectl accessCVE-2022-21953 · RancherHigh
- CRI-O: restored checkpoints re-apply archive mounts, bypassing pod-spec host mount validationCVE-2024-8676 · CRI-O (container checkpoint/restore endpoint)High
- Podman: files written to bind mounts during build persist in the host build context directoryCVE-2025-4953 · Podman (podman build, RUN --mount=type=bind)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.