PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73551 envoyproxy CVE debrief

CVE-2026-73551 is a path confusion issue in Envoy's URL normalization. A remote client can cause path confusion and bypass path-based security policy due to Envoy not recognizing dot and dotdot path segments with semicolon parameters. This issue is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. The vulnerability allows an attacker to manipulate URL paths, potentially leading to unauthorized access or other security issues. Defenders should assess their exposure and apply patches to prevent exploitation.

Vendor
envoyproxy
Product
envoy
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-28
Advisory published
2026-09-21
Advisory updated
2026-09-28

Who should care

Defenders responsible for Envoy instances should assess exposure and apply patches. This includes reviewing current configurations and updating to fixed versions. Additionally, security teams and vulnerability management teams should be aware of the potential impact and take necessary actions to prevent exploitation. Operators of Envoy instances should also review their configurations and update their systems to prevent potential security issues.

Why it matters

CVE-2026-73551 is a path confusion issue in Envoy's URL normalization that can cause path-based security policy bypass. Defenders should prioritize verifying exposure and applying patches for Envoy instances.

  • Path-based security policy bypass
  • Potential for unauthorized access
  • Need for verification of Envoy instance configurations
  • Priority for updating to fixed Envoy versions

Technical summary

Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon parameters. This can cause path confusion and bypass path-based security policy. The issue arises from Envoy's inability to properly handle semicolon parameters in certain path segments, allowing an attacker to manipulate URL paths. This vulnerability can be mitigated by updating to fixed versions of Envoy and reviewing current configurations and security policies. A remote client can exploit this vulnerability to cause path confusion and potentially bypass security measures.

Defensive priority

Defenders should prioritize verifying exposure and applying patches for Envoy instances. This involves reviewing current configurations, assessing potential impact, and updating to fixed versions.

Recommended defensive actions

  • Verify Envoy instance configurations and assess potential impact
  • Apply patches to update to Envoy versions 1.36.10, 1.37.6, 1.38.4, or 1.39.1
  • Review and update path-based security policies
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the path confusion issue in Envoy. The issue is caused by Envoy's URL normalization not recognizing dot and dotdot path segments with semicolon parameters.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73551 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73551

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73551 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73551

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.