Looking for the vulnerability index of Invicti's legacy products?
Envoy Proxy Improper Neutralization of Null Byte or NUL Character Vulnerability - CVE-2026-47778 - Vulnerability Database

Envoy Proxy Improper Neutralization of Null Byte or NUL Character Vulnerability - CVE-2026-47778

Medium
Reference: CVE-2026-47778
Title: Envoy Proxy Improper Neutralization of Null Byte or NUL Character Vulnerability
Overview:

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11 1.36.7 1.37.3 and 1.38.1 a structural flaw was identified in DefaultCertValidator::verifySubjectAltName where the extracted DNS SAN string is cast to a C-style string using .c_str() before being passed to the Utility::dnsNameMatch() algorithm. If the attacker serves a certificate with a dNSName SAN containing an embedded NUL byte the helper Utility::generalNameAsString captures the complete string including the NUL. However when .c_str() evaluates it implicit conversion to absl::string_view inside dnsNameMatch relies on strlen() prematurely truncating the evaluation context. Envoy evaluates trucated string against the exact required config_san match and returns true thereby successfully validating the string with the Nul byte for an upstream routing. This vulnerability is fixed in 1.35.11 1.36.7 1.37.3 and 1.38.1.