PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47775 Envoyproxy CVE debrief

CVE-2026-47775 is a vulnerability in Envoy's OAuth2 HTTP filter. The encrypt()/decrypt() functions use AES-256-CBC without an authentication tag, creating a padding oracle. An attacker can recover the plaintext PKCE code_verifier in ~6,200 requests and exchange it for a stolen authorization code to obtain the victim's access token. This issue affects Envoy versions prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1. The vulnerability has a CVSS score of 6.8 and is classified as MEDIUM severity. The CVE was published on June 26, 2026, and modified on June 29, 2026.

Vendor
Envoyproxy
Product
Envoy
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-26
Original CVE updated
2026-06-29
Advisory published
2026-06-26
Advisory updated
2026-06-29

Who should care

Users of Envoy, particularly those using the OAuth2 HTTP filter, should be aware of this vulnerability. Affected versions include Envoy 1.35.0 to 1.35.10, 1.36.0 to 1.36.6, 1.37.0 to 1.37.2, and 1.38.0. Upgrading to Envoy 1.35.11, 1.36.7, 1.37.3, or 1.38.1 or later will mitigate the issue.

Technical summary

The OAuth2 HTTP filter in Envoy uses AES-256-CBC for encryption and decryption without an authentication tag. This implementation creates a padding oracle vulnerability. An attacker who obtains the encrypted CodeVerifier cookie can exploit this vulnerability to recover the plaintext PKCE code_verifier in approximately 6,200 requests. With the recovered code_verifier, the attacker can exchange it with a stolen authorization code to obtain the victim's access token. The vulnerability is due to the lack of HMAC or AEAD in the encryption process.

Defensive priority

This vulnerability should be prioritized for remediation due to its MEDIUM severity and potential impact on access token security. Affected Envoy instances should be upgraded to a patched version as soon as possible.

Recommended defensive actions

  • Upgrade Envoy to version 1.35.11, 1.36.7, 1.37.3, or 1.38.1 or later.
  • Review and update access control and authentication mechanisms for the OAuth2 filter.
  • Monitor for suspicious activity related to the OAuth2 filter and access token requests.
  • Consider implementing additional security measures such as token blacklisting or revocation.
  • Verify that all instances of Envoy are running a patched version.

Evidence notes

The CVE-2026-47775 vulnerability was identified in Envoy's OAuth2 HTTP filter. The issue arises from the use of AES-256-CBC without an authentication tag, leading to a padding oracle vulnerability. The CVE was published on June 26, 2026, and modified on June 29, 2026. The vulnerability affects Envoy versions prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47775 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47775

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47775 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47775

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.