PatchSiren cyber security CVE debrief
CVE-2026-73546 Envoyproxy CVE debrief
CVE-2026-73546 is a high-severity vulnerability in Envoy, an open-source edge and service proxy. The vulnerability affects Envoy's /stats?format=html admin endpoint, which can be exploited by an attacker to execute script with the admin interface's origin and issue privileged same-origin requests. The issue is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
- Vendor
- Envoyproxy
- Product
- Envoy
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-10-05
Who should care
Operators and administrators of Envoy instances with browser-accessible admin interfaces and enabled components that persist attacker-influenced text in statistic names should assess exposure and prioritize remediation.
Why it matters
CVE-2026-73546 is a high-severity vulnerability in Envoy that allows for script execution with admin interface origin and privileged same-origin requests. Operators and administrators of Envoy instances with browser-accessible admin interfaces and enabled components that persist attacker-influenced text in statistic names should assess exposure and prioritize remediation.
- Script execution with admin interface origin
- Privileged same-origin requests
- Potential for data breaches or system compromise
- Need for verification of affected versions and exposure
Technical summary
The /stats?format=html admin endpoint in Envoy uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface's origin and issue privileged same-origin requests.
Defensive priority
Operators should assess exposure and prioritize remediation for Envoy instances with a browser-accessible admin interface and enabled components that persist attacker-influenced text in statistic names.
Recommended defensive actions
- Assess exposure of Envoy instances with browser-accessible admin interfaces and enabled components that persist attacker-influenced text in statistic names.
- Prioritize remediation for affected Envoy versions 1.36.0 to 1.36.9, 1.37.0 to 1.37.5, 1.38.0 to 1.38.3, and 1.39.0.
- Verify and apply patches to upgrade to Envoy versions 1.36.10, 1.37.6, 1.38.4, or 1.39.1.
- Monitor and restrict access to the /stats?format=html admin endpoint.
- Implement compensating controls, such as same-origin policy and Content Security Policy (CSP), to mitigate potential impacts.
Evidence notes
The CVE record and NVD vulnerability detail provide information on the vulnerability, its impact, and the fixed versions. The vulnerability affects Envoy's /stats?format=html admin endpoint, which can be exploited by an attacker to execute script with the admin interface's origin and issue privileged same-origin requests. The issue is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Operators and administrators of Envoy instances with browser-accessible admin interfaces and enabled components that persist attacker-influenc
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73546 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73546
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73546 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73546
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/11d34660ca0322eb125d045a564d9d87f016397f
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/884d30c56b835d5801733ae1dc38c94a08de23e8
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/9484e17c34353662f9bfd30c74f61fa8c9ee7b83
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/ab63a0e52b5a28472f2ff865b6464ae4004f7593
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.36.10
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.37.6
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.38.4
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.39.1
[email protected] - Release Notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.