CVE-2025-46821CWE-186

Envoy vulnerable to bypass of RBAC uri_template permission

Medium · published May 7, 2025

CVSS v3.1
5.3
EPSS
0%
Percentile
18.0
In the wild
Unconfirmed
What it is

Envoy is a cloud-native edge/middle/service proxy. Prior to versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8, Envoy's URI template matcher incorrectly excludes the `*` character from a set of valid characters in the URI path. As a result URI path containing the `*` character will not match a URI template expressions. This can result in bypass of RBAC rules when configured using the `uri_template` permissions. This vulnerability is fixed in Envoy versions v1.34.1, v1.33.3, v1.32.6, v1.31.8. As a workaround, configure additional RBAC permissions using `url_path` with `safe_regex` expression.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00263 · 18.0th percentile
Weakness
CWE-186 · Overly Restrictive Regular Expression
Published
2025-05-07T21:24Z
EPSS history
Timeline
  • 07 MAY 21:24Z
    Envoy vulnerable to bypass of RBAC uri_template permission
    cvelistv5