Looking for the vulnerability index of Invicti's legacy products?
Envoy : Improper Input Validation Vulnerability (CVE-2026-73552) - Vulnerability Database

Envoy : Improper Input Validation Vulnerability (CVE-2026-73552)

Description

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semantics. A downstream client can preserve a prohibited marker and add an unrelated obs-text octet, causing RE2::FullMatch to return false and a negative RBAC policy to treat the invalid subject as an ordinary no-match. A byte-oriented route matcher can s

References

Related Vulnerabilities