CVE-2026-73551

Source
https://cve.org/CVERecord?id=CVE-2026-73551
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73551.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73551
Aliases
  • GHSA-2w8w-rfw7-8gg4
Downstream
Related
Published
2026-09-21T20:17:02Z
Modified
2026-09-23T08:15:52Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Envoy: Path normalization does not handle dot and dotdot segments with parameters
Details

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon parameters. A request such as /user/..;foo=bar/admin is therefore not canonicalized to /admin even when path normalization is enabled. If an upstream interprets the segment according to RFC 3986 while Envoy applies routing or RBAC to the uncollapsed path, a remote client can cause path confusion and bypass path-based security policy. The relevant scope boundary is that the security consequence depends on a downstream/upstream path interpretation mismatch or a path-based Envoy decision. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-647"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73551.json"
}
References

Affected packages

Git / github.com/envoyproxy/envoy

Affected ranges

Type
GIT
Repo
https://github.com/envoyproxy/envoy
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.36.10"
        },
        {
            "introduced":  "1.37.0"
        },
        {
            "fixed":  "1.37.6"
        },
        {
            "introduced":  "1.38.0"
        },
        {
            "fixed":  "1.38.4"
        },
        {
            "introduced":  "1.39.0"
        },
        {
            "fixed":  "1.39.1"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0
v1.1.0
v1.10.0
v1.11.0
v1.12.0
v1.13.0
v1.14.0
v1.15.0
v1.16.0
v1.17.0
v1.18.0
v1.18.1
v1.18.2
v1.19.0
v1.2.0
v1.20.0
v1.21.0
v1.22.0
v1.23.0
v1.24.0
v1.25.0
v1.26.0
v1.27.0
v1.28.0
v1.29.0
v1.3.0
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.34.0
v1.35.0
v1.36.0
v1.36.1
v1.36.2
v1.36.3
v1.36.4
v1.36.5
v1.36.6
v1.36.7
v1.36.8
v1.36.9
v1.37.0
v1.37.1
v1.37.2
v1.37.3
v1.37.4
v1.37.5
v1.38.0
v1.38.1
v1.38.2
v1.38.3
v1.39.0
v1.4.0
v1.5.0
v1.6.0
v1.7.0
v1.8.0
v1.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73551.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "254951804697896146475277571172531230764",
                "170944659950646581942947640025153007403",
                "35773094236784813351781128619160740896",
                "255333843594855708596855189527218105380",
                "257251057925251734726546277829334744937",
                "63645269365551107873725124227815859338",
                "264826546536999875323504870233740876241",
                "187821676513527590255778910924496427367",
                "17154565687529368521756774478880258247",
                "296028225045099484088974783459687238423"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-0322a2ec",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
        "target":  {
            "file":  "source/common/http/path_utility.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "121095448681341609892884396130348258022",
                "35773094236784813351781128619160740896",
                "255333843594855708596855189527218105380",
                "257251057925251734726546277829334744937",
                "63645269365551107873725124227815859338",
                "264826546536999875323504870233740876241",
                "187821676513527590255778910924496427367",
                "17154565687529368521756774478880258247",
                "296028225045099484088974783459687238423"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-0934ca42",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
        "target":  {
            "file":  "source/common/http/path_utility.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "27097917056526876808592463285270741718",
            "length":  683
        },
        "id":  "CVE-2026-73551-0d66faae",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
        "target":  {
            "file":  "test/common/http/path_utility_test.cc",
            "function":  "TEST_F"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "273053205579456234137317339431060781847",
                "209645021865116091578734400939962708114",
                "113034644814002851648577037733708360489"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-0f8e93f7",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
        "target":  {
            "file":  "test/common/http/conn_manager_utility_test.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "326500070235833270721352183454513160993",
                "34221733497350993636970863623734246828",
                "304705615282888298069851074389413834378",
                "43000234343007445579583904442243575377",
                "258149916048960169229492004794874036068",
                "107239588533222764552993426738694574262",
                "106348753812866048303008680095914906080",
                "224872310450896847104376239441894125685",
                "115682162443706118131056104608184182464",
                "196362734273091655073878988830930654688",
                "311036092934859452523040386650597359485",
                "321266109746751379505217694627387619622",
                "245718074480400323208897969135421365550",
                "41483454443865021442319814274810288715",
                "110186300699507136176830115077878378555",
                "206977241603770274691160984572069157569",
                "87199031248590663755134380721802909778",
                "208538898478431645997128032476085490246"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-2039fab5",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
        "target":  {
            "file":  "test/common/http/path_utility_test.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "260694806746604016781097457348416439569",
                "43876405000182463110218190057717305935",
                "313091610287554724621441556006690524081"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-207b4365",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
        "target":  {
            "file":  "test/common/http/conn_manager_utility_test.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "326500070235833270721352183454513160993",
                "34221733497350993636970863623734246828",
                "304705615282888298069851074389413834378",
                "43000234343007445579583904442243575377",
                "258149916048960169229492004794874036068",
                "107239588533222764552993426738694574262",
                "106348753812866048303008680095914906080",
                "224872310450896847104376239441894125685",
                "115682162443706118131056104608184182464",
                "196362734273091655073878988830930654688",
                "311036092934859452523040386650597359485",
                "321266109746751379505217694627387619622",
                "245718074480400323208897969135421365550",
                "41483454443865021442319814274810288715",
                "110186300699507136176830115077878378555",
                "206977241603770274691160984572069157569",
                "87199031248590663755134380721802909778",
                "208538898478431645997128032476085490246"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-26f71be0",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
        "target":  {
            "file":  "test/common/http/path_utility_test.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "121095448681341609892884396130348258022",
                "35773094236784813351781128619160740896",
                "255333843594855708596855189527218105380",
                "257251057925251734726546277829334744937",
                "63645269365551107873725124227815859338",
                "264826546536999875323504870233740876241",
                "187821676513527590255778910924496427367",
                "17154565687529368521756774478880258247",
                "296028225045099484088974783459687238423"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-28ab78c1",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
        "target":  {
            "file":  "source/common/http/path_utility.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "260694806746604016781097457348416439569",
                "43876405000182463110218190057717305935",
                "313091610287554724621441556006690524081"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-3619419a",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
        "target":  {
            "file":  "test/common/http/conn_manager_utility_test.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "27097917056526876808592463285270741718",
            "length":  683
        },
        "id":  "CVE-2026-73551-36ff5064",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
        "target":  {
            "file":  "test/common/http/path_utility_test.cc",
            "function":  "TEST_F"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "234907012746348227178463390021484710498",
                "197141251971384012639870804435285690917",
                "98723685267585265733076664510276605259",
                "145635871549315223777346769321984975660"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-3ea640e5",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
        "target":  {
            "file":  "source/common/http/path_utility.h"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "121095448681341609892884396130348258022",
                "35773094236784813351781128619160740896",
                "255333843594855708596855189527218105380",
                "257251057925251734726546277829334744937",
                "63645269365551107873725124227815859338",
                "264826546536999875323504870233740876241",
                "187821676513527590255778910924496427367",
                "17154565687529368521756774478880258247",
                "296028225045099484088974783459687238423"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-4cdc8f21",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
        "target":  {
            "file":  "source/common/http/path_utility.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "326500070235833270721352183454513160993",
                "34221733497350993636970863623734246828",
                "304705615282888298069851074389413834378",
                "43000234343007445579583904442243575377",
                "258149916048960169229492004794874036068",
                "107239588533222764552993426738694574262",
                "106348753812866048303008680095914906080",
                "224872310450896847104376239441894125685",
                "115682162443706118131056104608184182464",
                "196362734273091655073878988830930654688",
                "311036092934859452523040386650597359485",
                "321266109746751379505217694627387619622",
                "245718074480400323208897969135421365550",
                "41483454443865021442319814274810288715",
                "110186300699507136176830115077878378555",
                "206977241603770274691160984572069157569",
                "87199031248590663755134380721802909778",
                "208538898478431645997128032476085490246"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-51eaa1c6",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
        "target":  {
            "file":  "test/common/http/path_utility_test.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "234907012746348227178463390021484710498",
                "197141251971384012639870804435285690917",
                "98723685267585265733076664510276605259",
                "145635871549315223777346769321984975660"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-54a173f7",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
        "target":  {
            "file":  "source/common/http/path_utility.h"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "330015756055329241503614684831531901966",
                "259804798515067152997678676672894252347",
                "92717807670919798956366411669519226052",
                "248190880920182074907612219961018086528"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-68be4b70",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
        "target":  {
            "file":  "source/common/runtime/runtime_features.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "234907012746348227178463390021484710498",
                "197141251971384012639870804435285690917",
                "98723685267585265733076664510276605259",
                "145635871549315223777346769321984975660"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-6adda5ef",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
        "target":  {
            "file":  "source/common/http/path_utility.h"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "273053205579456234137317339431060781847",
                "209645021865116091578734400939962708114",
                "113034644814002851648577037733708360489"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-6f3eeb20",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
        "target":  {
            "file":  "test/common/http/conn_manager_utility_test.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "179076496298280788163404611175858448145",
                "247207119516896101820036844433237590243",
                "64549989772869634695418590268724725377",
                "217327943411520342925502178573576297582"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-70d25390",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
        "target":  {
            "file":  "source/common/runtime/runtime_features.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "326500070235833270721352183454513160993",
                "34221733497350993636970863623734246828",
                "304705615282888298069851074389413834378",
                "43000234343007445579583904442243575377",
                "258149916048960169229492004794874036068",
                "107239588533222764552993426738694574262",
                "106348753812866048303008680095914906080",
                "224872310450896847104376239441894125685",
                "115682162443706118131056104608184182464",
                "196362734273091655073878988830930654688",
                "311036092934859452523040386650597359485",
                "321266109746751379505217694627387619622",
                "245718074480400323208897969135421365550",
                "41483454443865021442319814274810288715",
                "110186300699507136176830115077878378555",
                "206977241603770274691160984572069157569",
                "87199031248590663755134380721802909778",
                "208538898478431645997128032476085490246"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-79a038f2",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
        "target":  {
            "file":  "test/common/http/path_utility_test.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "228366476279792466598722624014911220154",
            "length":  667
        },
        "id":  "CVE-2026-73551-87f4411f",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
        "target":  {
            "file":  "source/common/http/path_utility.cc",
            "function":  "PathUtil::canonicalPath"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "228366476279792466598722624014911220154",
            "length":  667
        },
        "id":  "CVE-2026-73551-a1b38a89",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
        "target":  {
            "file":  "source/common/http/path_utility.cc",
            "function":  "PathUtil::canonicalPath"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "228366476279792466598722624014911220154",
            "length":  667
        },
        "id":  "CVE-2026-73551-adddc3da",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
        "target":  {
            "file":  "source/common/http/path_utility.cc",
            "function":  "PathUtil::canonicalPath"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "27097917056526876808592463285270741718",
            "length":  683
        },
        "id":  "CVE-2026-73551-ba971489",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/d40a68b0a30a003c4e0a9fd3af637f828b52c37b",
        "target":  {
            "file":  "test/common/http/path_utility_test.cc",
            "function":  "TEST_F"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "27097917056526876808592463285270741718",
            "length":  683
        },
        "id":  "CVE-2026-73551-bd0ff753",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
        "target":  {
            "file":  "test/common/http/path_utility_test.cc",
            "function":  "TEST_F"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "234907012746348227178463390021484710498",
                "197141251971384012639870804435285690917",
                "98723685267585265733076664510276605259",
                "145635871549315223777346769321984975660"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-cf64ec0f",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/e9d6c329f9a3ff19432bf39b60c601df7e3eda33",
        "target":  {
            "file":  "source/common/http/path_utility.h"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "228366476279792466598722624014911220154",
            "length":  667
        },
        "id":  "CVE-2026-73551-eab19f07",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
        "target":  {
            "file":  "source/common/http/path_utility.cc",
            "function":  "PathUtil::canonicalPath"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "28870506486777150777589946109606173547",
                "31895635636710191765386035532709825550",
                "4266904828304254280019566869153278389",
                "26422062265085471630342419877470975791"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-f2e7ad5a",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/f74d1107c4f5c9679b66f7a03a6c5b75ddde1989",
        "target":  {
            "file":  "source/common/runtime/runtime_features.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "140473620424856378536004687506651319159",
                "270117008251974779420011940158249857018",
                "22785559159782107717189257970756126778",
                "217308994167056837072657692098387353804"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-73551-f3e5afef",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/envoyproxy/envoy/commit/28b6d60a6d96edeece121cac5be701eb46cc7f24",
        "target":  {
            "file":  "source/common/runtime/runtime_features.cc"
        }
    }
]
vanir_signatures_modified
"2026-09-23T08:15:52Z"