Incorrect Authorization Affecting envoyproxy/envoy package, versions [,1.34.13)[1.35.0,1.35.9)[1.36.0,1.36.5)[1.37.0,1.37.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.29% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-ENVOYPROXYENVOY-15466853
  • published12 Mar 2026
  • disclosed10 Mar 2026
  • creditUnknown

Introduced: 10 Mar 2026

CVE-2026-26308  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade envoyproxy/envoy to version 1.34.13, 1.35.9, 1.36.5, 1.37.1 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization in the RBAC filter's handling of HTTP headers when multiple values are present for the same header name. An attacker can bypass access control policies by sending duplicate headers, causing the system to concatenate values and obscure malicious content from exact-match checks.

References

CVSS Base Scores

version 4.0
version 3.1