Envoy Proxy URI Path Validation Issue in Envoy Proxy
CVE-2025-46821
What is CVE-2025-46821?
Envoy Proxy's URI template matcher exhibits a flaw that inadequately validates the * character within URI paths. Before the fixed versions, URIs containing this character would not comply with URI template expressions, potentially leading to unauthorized access through the bypass of role-based access control (RBAC) rules. This vulnerability emphasizes the importance of configuring additional permissions using url_path with a safe_regex expression as a workaround. The issue has been rectified in Envoy versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
envoy < 1.31.8 < 1.31.8
envoy >= 1.32.0, < 1.32.6 < 1.32.0, 1.32.6
envoy >= 1.33.0, < 1.33.3 < 1.33.0, 1.33.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
