PatchSiren cyber security CVE debrief
CVE-2026-47775 Envoyproxy CVE debrief
CVE-2026-47775 is a vulnerability in Envoy's OAuth2 HTTP filter. The encrypt()/decrypt() functions use AES-256-CBC without an authentication tag, creating a padding oracle. An attacker can recover the plaintext PKCE code_verifier in ~6,200 requests and exchange it for a stolen authorization code to obtain the victim's access token. This issue affects Envoy versions prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1. The vulnerability has a CVSS score of 6.8 and is classified as MEDIUM severity. The CVE was published on June 26, 2026, and modified on June 29, 2026.
- Vendor
- Envoyproxy
- Product
- Envoy
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-26
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-26
- Advisory updated
- 2026-06-29
Who should care
Users of Envoy, particularly those using the OAuth2 HTTP filter, should be aware of this vulnerability. Affected versions include Envoy 1.35.0 to 1.35.10, 1.36.0 to 1.36.6, 1.37.0 to 1.37.2, and 1.38.0. Upgrading to Envoy 1.35.11, 1.36.7, 1.37.3, or 1.38.1 or later will mitigate the issue.
Technical summary
The OAuth2 HTTP filter in Envoy uses AES-256-CBC for encryption and decryption without an authentication tag. This implementation creates a padding oracle vulnerability. An attacker who obtains the encrypted CodeVerifier cookie can exploit this vulnerability to recover the plaintext PKCE code_verifier in approximately 6,200 requests. With the recovered code_verifier, the attacker can exchange it with a stolen authorization code to obtain the victim's access token. The vulnerability is due to the lack of HMAC or AEAD in the encryption process.
Defensive priority
This vulnerability should be prioritized for remediation due to its MEDIUM severity and potential impact on access token security. Affected Envoy instances should be upgraded to a patched version as soon as possible.
Recommended defensive actions
- Upgrade Envoy to version 1.35.11, 1.36.7, 1.37.3, or 1.38.1 or later.
- Review and update access control and authentication mechanisms for the OAuth2 filter.
- Monitor for suspicious activity related to the OAuth2 filter and access token requests.
- Consider implementing additional security measures such as token blacklisting or revocation.
- Verify that all instances of Envoy are running a patched version.
Evidence notes
The CVE-2026-47775 vulnerability was identified in Envoy's OAuth2 HTTP filter. The issue arises from the use of AES-256-CBC without an authentication tag, leading to a padding oracle vulnerability. The CVE was published on June 26, 2026, and modified on June 29, 2026. The vulnerability affects Envoy versions prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47775 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47775
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47775 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47775
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/security/advisories/GHSA-396h-jpq4-vc7p
[email protected] - Exploit, Vendor Advisory, Mitigation
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.