Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon parameters. A request such as /user/..;foo=bar/admin is therefore not canonicalized to /admin even when path normalization is enabled. If an upstream interprets the segment according to RFC 3986 while Envoy applies routing or RBAC to the uncollapsed path, a remote client can cause path confusion and bypass path-based security policy. The relevant scope boundary is that the security consequence depends on a downstream/upstream path interpretation mismatch or a path-based Envoy decision. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-647"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73551.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.36.10"
},
{
"introduced": "1.37.0"
},
{
"fixed": "1.37.6"
},
{
"introduced": "1.38.0"
},
{
"fixed": "1.38.4"
},
{
"introduced": "1.39.0"
},
{
"fixed": "1.39.1"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73551.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"254951804697896146475277571172531230764",
"170944659950646581942947640025153007403",
"35773094236784813351781128619160740896",
"255333843594855708596855189527218105380",
"257251057925251734726546277829334744937",
"63645269365551107873725124227815859338",
"264826546536999875323504870233740876241",
"187821676513527590255778910924496427367",
"17154565687529368521756774478880258247",
"296028225045099484088974783459687238423"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-0322a2ec",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
"target": {
"file": "source/common/http/path_utility.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"121095448681341609892884396130348258022",
"35773094236784813351781128619160740896",
"255333843594855708596855189527218105380",
"257251057925251734726546277829334744937",
"63645269365551107873725124227815859338",
"264826546536999875323504870233740876241",
"187821676513527590255778910924496427367",
"17154565687529368521756774478880258247",
"296028225045099484088974783459687238423"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-0934ca42",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
"target": {
"file": "source/common/http/path_utility.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "27097917056526876808592463285270741718",
"length": 683
},
"id": "CVE-2026-73551-0d66faae",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
"target": {
"file": "test/common/http/path_utility_test.cc",
"function": "TEST_F"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"273053205579456234137317339431060781847",
"209645021865116091578734400939962708114",
"113034644814002851648577037733708360489"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-0f8e93f7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
"target": {
"file": "test/common/http/conn_manager_utility_test.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"326500070235833270721352183454513160993",
"34221733497350993636970863623734246828",
"304705615282888298069851074389413834378",
"43000234343007445579583904442243575377",
"258149916048960169229492004794874036068",
"107239588533222764552993426738694574262",
"106348753812866048303008680095914906080",
"224872310450896847104376239441894125685",
"115682162443706118131056104608184182464",
"196362734273091655073878988830930654688",
"311036092934859452523040386650597359485",
"321266109746751379505217694627387619622",
"245718074480400323208897969135421365550",
"41483454443865021442319814274810288715",
"110186300699507136176830115077878378555",
"206977241603770274691160984572069157569",
"87199031248590663755134380721802909778",
"208538898478431645997128032476085490246"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-2039fab5",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
"target": {
"file": "test/common/http/path_utility_test.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"260694806746604016781097457348416439569",
"43876405000182463110218190057717305935",
"313091610287554724621441556006690524081"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-207b4365",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
"target": {
"file": "test/common/http/conn_manager_utility_test.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"326500070235833270721352183454513160993",
"34221733497350993636970863623734246828",
"304705615282888298069851074389413834378",
"43000234343007445579583904442243575377",
"258149916048960169229492004794874036068",
"107239588533222764552993426738694574262",
"106348753812866048303008680095914906080",
"224872310450896847104376239441894125685",
"115682162443706118131056104608184182464",
"196362734273091655073878988830930654688",
"311036092934859452523040386650597359485",
"321266109746751379505217694627387619622",
"245718074480400323208897969135421365550",
"41483454443865021442319814274810288715",
"110186300699507136176830115077878378555",
"206977241603770274691160984572069157569",
"87199031248590663755134380721802909778",
"208538898478431645997128032476085490246"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-26f71be0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
"target": {
"file": "test/common/http/path_utility_test.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"121095448681341609892884396130348258022",
"35773094236784813351781128619160740896",
"255333843594855708596855189527218105380",
"257251057925251734726546277829334744937",
"63645269365551107873725124227815859338",
"264826546536999875323504870233740876241",
"187821676513527590255778910924496427367",
"17154565687529368521756774478880258247",
"296028225045099484088974783459687238423"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-28ab78c1",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
"target": {
"file": "source/common/http/path_utility.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"260694806746604016781097457348416439569",
"43876405000182463110218190057717305935",
"313091610287554724621441556006690524081"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-3619419a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
"target": {
"file": "test/common/http/conn_manager_utility_test.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "27097917056526876808592463285270741718",
"length": 683
},
"id": "CVE-2026-73551-36ff5064",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
"target": {
"file": "test/common/http/path_utility_test.cc",
"function": "TEST_F"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"234907012746348227178463390021484710498",
"197141251971384012639870804435285690917",
"98723685267585265733076664510276605259",
"145635871549315223777346769321984975660"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-3ea640e5",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
"target": {
"file": "source/common/http/path_utility.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"121095448681341609892884396130348258022",
"35773094236784813351781128619160740896",
"255333843594855708596855189527218105380",
"257251057925251734726546277829334744937",
"63645269365551107873725124227815859338",
"264826546536999875323504870233740876241",
"187821676513527590255778910924496427367",
"17154565687529368521756774478880258247",
"296028225045099484088974783459687238423"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-4cdc8f21",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
"target": {
"file": "source/common/http/path_utility.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"326500070235833270721352183454513160993",
"34221733497350993636970863623734246828",
"304705615282888298069851074389413834378",
"43000234343007445579583904442243575377",
"258149916048960169229492004794874036068",
"107239588533222764552993426738694574262",
"106348753812866048303008680095914906080",
"224872310450896847104376239441894125685",
"115682162443706118131056104608184182464",
"196362734273091655073878988830930654688",
"311036092934859452523040386650597359485",
"321266109746751379505217694627387619622",
"245718074480400323208897969135421365550",
"41483454443865021442319814274810288715",
"110186300699507136176830115077878378555",
"206977241603770274691160984572069157569",
"87199031248590663755134380721802909778",
"208538898478431645997128032476085490246"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-51eaa1c6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
"target": {
"file": "test/common/http/path_utility_test.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"234907012746348227178463390021484710498",
"197141251971384012639870804435285690917",
"98723685267585265733076664510276605259",
"145635871549315223777346769321984975660"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-54a173f7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
"target": {
"file": "source/common/http/path_utility.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"330015756055329241503614684831531901966",
"259804798515067152997678676672894252347",
"92717807670919798956366411669519226052",
"248190880920182074907612219961018086528"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-68be4b70",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
"target": {
"file": "source/common/runtime/runtime_features.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"234907012746348227178463390021484710498",
"197141251971384012639870804435285690917",
"98723685267585265733076664510276605259",
"145635871549315223777346769321984975660"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-6adda5ef",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
"target": {
"file": "source/common/http/path_utility.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"273053205579456234137317339431060781847",
"209645021865116091578734400939962708114",
"113034644814002851648577037733708360489"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-6f3eeb20",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
"target": {
"file": "test/common/http/conn_manager_utility_test.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"179076496298280788163404611175858448145",
"247207119516896101820036844433237590243",
"64549989772869634695418590268724725377",
"217327943411520342925502178573576297582"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-70d25390",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
"target": {
"file": "source/common/runtime/runtime_features.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"326500070235833270721352183454513160993",
"34221733497350993636970863623734246828",
"304705615282888298069851074389413834378",
"43000234343007445579583904442243575377",
"258149916048960169229492004794874036068",
"107239588533222764552993426738694574262",
"106348753812866048303008680095914906080",
"224872310450896847104376239441894125685",
"115682162443706118131056104608184182464",
"196362734273091655073878988830930654688",
"311036092934859452523040386650597359485",
"321266109746751379505217694627387619622",
"245718074480400323208897969135421365550",
"41483454443865021442319814274810288715",
"110186300699507136176830115077878378555",
"206977241603770274691160984572069157569",
"87199031248590663755134380721802909778",
"208538898478431645997128032476085490246"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-79a038f2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
"target": {
"file": "test/common/http/path_utility_test.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "228366476279792466598722624014911220154",
"length": 667
},
"id": "CVE-2026-73551-87f4411f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
"target": {
"file": "source/common/http/path_utility.cc",
"function": "PathUtil::canonicalPath"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "228366476279792466598722624014911220154",
"length": 667
},
"id": "CVE-2026-73551-a1b38a89",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
"target": {
"file": "source/common/http/path_utility.cc",
"function": "PathUtil::canonicalPath"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "228366476279792466598722624014911220154",
"length": 667
},
"id": "CVE-2026-73551-adddc3da",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
"target": {
"file": "source/common/http/path_utility.cc",
"function": "PathUtil::canonicalPath"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "27097917056526876808592463285270741718",
"length": 683
},
"id": "CVE-2026-73551-ba971489",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
"target": {
"file": "test/common/http/path_utility_test.cc",
"function": "TEST_F"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "27097917056526876808592463285270741718",
"length": 683
},
"id": "CVE-2026-73551-bd0ff753",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
"target": {
"file": "test/common/http/path_utility_test.cc",
"function": "TEST_F"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"234907012746348227178463390021484710498",
"197141251971384012639870804435285690917",
"98723685267585265733076664510276605259",
"145635871549315223777346769321984975660"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-cf64ec0f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
"target": {
"file": "source/common/http/path_utility.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "228366476279792466598722624014911220154",
"length": 667
},
"id": "CVE-2026-73551-eab19f07",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
"target": {
"file": "source/common/http/path_utility.cc",
"function": "PathUtil::canonicalPath"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"28870506486777150777589946109606173547",
"31895635636710191765386035532709825550",
"4266904828304254280019566869153278389",
"26422062265085471630342419877470975791"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-f2e7ad5a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
"target": {
"file": "source/common/runtime/runtime_features.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"140473620424856378536004687506651319159",
"270117008251974779420011940158249857018",
"22785559159782107717189257970756126778",
"217308994167056837072657692098387353804"
],
"threshold": 0.9
},
"id": "CVE-2026-73551-f3e5afef",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
"target": {
"file": "source/common/runtime/runtime_features.cc"
}
}
]
"2026-09-23T08:15:52Z"