CVE-2026-26308Disclosure(envoyproxy / envoy)

LOWCVSS 8.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch envoyproxy envoy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically "Deny" rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • envoy

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
envoy

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-10: 3Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-10: 103-10
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-26308: Envoy Proxy merges duplicate headers, letting attackers bypass RBAC Deny rules and reach protected services. Update to 1.37.1 / 1.36.5 / 1.35.9 / 1.34.13 or enable rbac_match_headers_individually. More info ➡️ https://volerion.com/vulnerabilities/CVE-2026-26308 #Envoy #infosec #DevOps

    Post summary

    The tweet announces CVE-2026-26308, details the bypass of RBAC rules via duplicate header merging, and provides specific Envoy patch versions and a configuration workaround.

    01010131
    50 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26308 Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logi… https://www.cve.org/CVERecord?id=CVE-2026-26308 ----- Traducción: CVE-2026-26308 Env… http://infoflow.cloud`

    Post summary

    The tweet announces the existence of CVE-2026-26308 for Envoy, lists affected versions, and directs readers to the CVE record, but provides no further technical detail or indicators of exploitation.

    0000015
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26308 Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logi… https://www.cve.org/CVERecord?id=CVE-2026-26308

    Post summary

    The tweet announces CVE-2026‑26308 as a flaw in Envoy’s RBAC filter affecting older releases, but offers no technical depth, PoC, exploit, or mitigation information.

    00000201
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appenvoyproxyenvoy---
Appenvoyproxyenvoy1.37.0--

Explore more