CVE-2026-73546
Last modified
CVE-2026-73546 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component such as grpc_stats with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface's origin and issue privileged same-origin requests. The relevant scope boundary is that the admin interface must be browser-accessible and an enabled component must persist attacker-influenced text in statistic names. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| envoyproxy | envoy | < 1.36.10; >= 1.37.0, < 1.37.6; >= 1.38.0, < 1.38.4; >= 1.39.0, < 1.39.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-73546?
How severe is CVE-2026-73546?
How do I fix CVE-2026-73546?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73532Fluent Forms Pro 6.2.7 contains an embedded malicious code v…9.8
- CVE-2026-73533Ninja Tables Pro 5.2.11 contains an embedded malicious code …9.8
- CVE-2026-73537Cross-site scripting vulnerability exists in Miraikan Assist…5.1
- CVE-2026-7354Out of bounds read and write in Angle in Google Chrome prior…8.8
- CVE-2026-73541Allocation of Resources Without Limits or Throttling in ZenH…8.2
- CVE-2026-73542Multiple SEIKO EPSON printers and scanners contain revoked r…3.7
- CVE-2026-73547Envoy is an open source edge and service proxy designed for …7.5
- CVE-2026-73548Envoy is an open source edge and service proxy designed for …7.5
- CVE-2026-73549Envoy is an open source edge and service proxy designed for …5.3
- CVE-2026-7355Use after free in Media in Google Chrome prior to 147.0.7727…8.8
- CVE-2026-73550Envoy is an open source edge and service proxy designed for …7.5
- CVE-2026-73551Envoy is an open source edge and service proxy designed for …5.3
Are you affected by CVE-2026-73546?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
