CVE-2026-73547: Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check

Published Sep 21, 2026
·
Updated

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's extauthz filter assumes that a request contains a :path pseudoheader when applying queryparameterstoset or queryparameterstoremove from an authorization response. A path-less CONNECT request makes requestheaders->Path() return null, and Filter::onComplete dereferences that pointer while parsing the query string. An unauthenticated downstream client can crash the Envoy process when the filter and authorization response use query-parameter mutation. The relevant scope boundary is that the deployment must accept path-less CONNECT and configure extauthz query-parameter mutation. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

Affected Software

4 affected components
Envoy Envoy<1.36.10
Envoy Envoy>1.36.10<1.37.6
Envoy Envoy>1.37.6<1.38.4
Envoy Envoy>1.38.4<1.39.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Envoy to a version that resolves this vulnerability.

    Fixed in 1.36.10
  2. Upgrade

    Upgrade Envoy to a version that resolves this vulnerability.

    Fixed in 1.37.6
  3. Upgrade

    Upgrade Envoy to a version that resolves this vulnerability.

    Fixed in 1.38.4
  4. Upgrade

    Upgrade Envoy to a version that resolves this vulnerability.

    Fixed in 1.39.1

Event History

Sep 21, 2026
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this denial-of-service issue?

A deployment is exposed only if it accepts path-less CONNECT requests and uses the ext_authz filter with authorization responses that apply query_parameters_to_set or query_parameters_to_remove. An unauthenticated downstream client can trigger the crash under those conditions.

2

What is required to exploit the issue?

The attacker needs network access to send a path-less CONNECT request to the Envoy deployment. No authentication or user interaction is required.

3

What should be changed if upgrading is not immediately possible?

Mitigate exposure by preventing acceptance of path-less CONNECT requests or by avoiding ext_authz authorization-response query-parameter mutation through query_parameters_to_set and query_parameters_to_remove. The provided data does not identify other mitigations.

4

Which versions contain the fix?

The issue is fixed in Envoy 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203