
🚨 CVE-2026-26308: Envoy Proxy merges duplicate headers, letting attackers bypass RBAC Deny rules and reach protected services. Update to 1.37.1 / 1.36.5 / 1.35.9 / 1.34.13 or enable rbac_match_headers_individually. More info ➡️ https://volerion.com/vulnerabilities/CVE-2026-26308 #Envoy #infosec #DevOps
Post summary
The tweet announces CVE-2026-26308, details the bypass of RBAC rules via duplicate header merging, and provides specific Envoy patch versions and a configuration workaround.


