CVE-2026-73552
Last modified
CVE-2026-73552 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semantics. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semantics. A downstream client can preserve a prohibited marker and add an unrelated obs-text octet, causing RE2::FullMatch to return false and a negative RBAC policy to treat the invalid subject as an ordinary no-match. A byte-oriented route matcher can still observe the marker, allowing the request to reach a route intended to be denied. The relevant scope boundary is that plain positive ALLOW regexes normally fail closed, and exact, prefix, suffix, and contains matchers are not shown to have this subject-domain failure. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| envoyproxy | envoy | < 1.36.10; >= 1.37.0, < 1.37.6; >= 1.38.0, < 1.38.4; >= 1.39.0, < 1.39.1 |
References
Timeline
- Published
- Last Modified
- Status
- Undergoing Analysis
Frequently Asked Questions
What is CVE-2026-73552?
How severe is CVE-2026-73552?
How do I fix CVE-2026-73552?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73547Envoy is an open source edge and service proxy designed for …7.5
- CVE-2026-73548Envoy is an open source edge and service proxy designed for …7.5
- CVE-2026-73549Envoy is an open source edge and service proxy designed for …5.3
- CVE-2026-7355Use after free in Media in Google Chrome prior to 147.0.7727…8.8
- CVE-2026-73550Envoy is an open source edge and service proxy designed for …7.5
- CVE-2026-73551Envoy is an open source edge and service proxy designed for …5.3
- CVE-2026-73553Envoy is an open source edge and service proxy designed for …7.5
- CVE-2026-73555vLLM is an inference and serving engine for large language m…5.3
- CVE-2026-73556vLLM is an inference and serving engine for large language m…5.3
- CVE-2026-73557vLLM is an inference and serving engine for large language m…6.3
- CVE-2026-73558vLLM is an inference and serving engine for large language m…5.3
- CVE-2026-73559vLLM is an inference and serving engine for large language m…6.5
Are you affected by CVE-2026-73552?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
