We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-46821

Envoy vulnerable to bypass of RBAC uri_template permission



Description

Envoy is a cloud-native edge/middle/service proxy. Prior to versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8, Envoy's URI template matcher incorrectly excludes the `*` character from a set of valid characters in the URI path. As a result URI path containing the `*` character will not match a URI template expressions. This can result in bypass of RBAC rules when configured using the `uri_template` permissions. This vulnerability is fixed in Envoy versions v1.34.1, v1.33.3, v1.32.6, v1.31.8. As a workaround, configure additional RBAC permissions using `url_path` with `safe_regex` expression.

Reserved 2025-04-30 | Published 2025-05-07 | Updated 2025-05-08 | Assigner GitHub_M


MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-186: Overly Restrictive Regular Expression

Product status

< 1.31.8
affected

>= 1.32.0, < 1.32.6
affected

>= 1.33.0, < 1.33.3
affected

>= 1.34.0, < 1.34.1
affected

References

github.com/.../envoy/security/advisories/GHSA-c7cm-838g-6g67

cve.org (CVE-2025-46821)

nvd.nist.gov (CVE-2025-46821)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-46821

Support options

Helpdesk Chat, Email, Knowledgebase