Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies—specifically "Deny" rules—by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.
{
"cwe_ids": [
"CWE-863"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26308.json"
}{
"cpe": [
"cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*",
"cpe:2.3:a:envoyproxy:envoy:1.37.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.34.13"
},
{
"introduced": "1.35.0"
},
{
"fixed": "1.35.8"
},
{
"introduced": "1.36.0"
},
{
"fixed": "1.36.5"
},
{
"introduced": "1.37.0"
},
{
"last_affected": "1.37.0"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
]
}"2026-07-16T00:03:45Z"
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"307993278646808064273918717381878634534",
"93966140253654315037002192513861528773",
"94157562991279752868771655872517105857",
"266042391640566171413120697661715997046",
"281928225354114759985217343597918252883",
"26931787561531805013053852709920780261"
]
},
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/b6ba0b2294b98484fb0ed8556897d1073cc27867",
"id": "CVE-2026-26308-15fec99b",
"target": {
"file": "source/common/http/header_utility.h"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"331784845532747690511365370713018762015",
"32016695196553354873907498678782425890",
"238550549931939169309634354367918055721",
"205459903706198659916698677138889763768",
"327540819630509000694278953375045971202",
"121468385808218468450195827435775983915",
"145684759757382830150162795105163887696",
"155434208676838736010779821591969519354",
"167119706264252282889535574080480925109"
]
},
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/b6ba0b2294b98484fb0ed8556897d1073cc27867",
"id": "CVE-2026-26308-1d9050e3",
"target": {
"file": "source/extensions/filters/common/rbac/matchers.h"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"63350482614684853589080884968993691136",
"274621385026985150605388013864626608087",
"30194948638454257386779764387151425144",
"221187988563176933400201284535489390631"
]
},
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/b6ba0b2294b98484fb0ed8556897d1073cc27867",
"id": "CVE-2026-26308-3b8f6488",
"target": {
"file": "source/common/runtime/runtime_features.cc"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"319916229507619455485150288447908852694",
"7822889389478140330478805139926222365",
"330804399155879790691254347699106084369"
]
},
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/b6ba0b2294b98484fb0ed8556897d1073cc27867",
"id": "CVE-2026-26308-5aee358a",
"target": {
"file": "test/extensions/filters/common/rbac/matchers_test.cc"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"123681333993630434883126451148456745127",
"176402239509480841329196599773201997150",
"326272921497272327569387017379014016221"
]
},
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/b6ba0b2294b98484fb0ed8556897d1073cc27867",
"id": "CVE-2026-26308-74677230",
"target": {
"file": "test/common/http/header_utility_test.cc"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"113972512269161541748225039007176214253",
"251781383151711670630223209923564123317",
"144953606160475839163036141392730252427",
"244772715440972028247835740794047149917",
"103709824501716579595453039284462618410",
"184934869710487780104910894321294393560"
]
},
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/b6ba0b2294b98484fb0ed8556897d1073cc27867",
"id": "CVE-2026-26308-82e207b5",
"target": {
"file": "test/extensions/filters/http/rbac/rbac_filter_integration_test.cc"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 141.0,
"function_hash": "2636148190921487010531923718541353785"
},
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/b6ba0b2294b98484fb0ed8556897d1073cc27867",
"id": "CVE-2026-26308-aa6d49e0",
"target": {
"function": "HeaderMatcher::matches",
"file": "source/extensions/filters/common/rbac/matchers.cc"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"339774293788940641181549077199716704174",
"103547314086159498647374723623263326759",
"90010073243512176453796892685853014691",
"268912331777502240978657112028227592712",
"246714598471284408576981357761520398648",
"201380783952932465387025946168456931009",
"177781130313580876890219137174234923767",
"118937163696031249535077225779442556847",
"260018622786342720680560213460204060791",
"66153436295360759956019924662611022470"
]
},
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/b6ba0b2294b98484fb0ed8556897d1073cc27867",
"id": "CVE-2026-26308-cd053573",
"target": {
"file": "source/extensions/filters/common/rbac/matchers.cc"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"290197355003660930592911448274699094308",
"172895980987054801544210323060019839530",
"92671839262669939685194527957196284514",
"105516405803016880189865712323658473841"
]
},
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/b6ba0b2294b98484fb0ed8556897d1073cc27867",
"id": "CVE-2026-26308-d26f6557",
"target": {
"file": "envoy/http/header_map.h"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26308.json"