boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-73553

envoyproxy envoy — Envoy: RBAC Authorization Bypass via Path Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  L  N    7.5   .0051   41.4     —
AFFECTED
  Product  Versions     Fixed
  envoy    < 1.36.10 –  —
TIMELINE
  Aug 12  Reserved by GitHub_M
  Sep 21  Published (CNA: GitHub_M)
  Oct 5   EXPLOIT PUBLISHED — CVE-2026-73553 (envoyproxy envoy). Public exploit reference added.
CWE-436 · CNA: GitHub_M · CVSS v3.1 · 9 references · NVD status: Analyzed

Description

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix before matching but the RBAC url_path matcher evaluates the raw path. A downstream request such as /admin;x can therefore miss a DENY rule for /admin while the router still selects the protected /admin backend. The inconsistent canonicalization allows an unauthenticated client to bypass path-based authorization. The relevant scope boundary is that the route option and a path-based RBAC rule must both be present, and the protected route must match after stripping. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 12, 2026ReservedReserved by GitHub_M
September 21, 2026PublishedPublished (CNA: GitHub_M)
October 5, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-73553 (envoyproxy envoy). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
envoyproxyenvoy—< 1.36.10—

Weaknesses

CWE-436

References (9)

Related

Authoritative record: CVE-2026-73553 at cve.org

Vendors: envoyproxy

Weaknesses: CWE-436

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-73553 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.