Impact
The path matching bypass in Envoy’s router allows an actor to craft URLs that include per‑segment parameters not stripped during routing, which may cause the router to match a request to an unintended route. This flaw, classified under CWE‑706, could potentially enable an attacker to bypass authentication or authorization controls by reaching protected endpoints that should be inaccessible. The documented impact is an elevation of privilege that could expose sensitive data or services.
Affected Systems
The vulnerability targets the Envoy proxy server. No specific affected versions are listed in the available data, so any deployment that has not verified its patch status should be treated as potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 points to a moderate severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, indicating no confirmed exploits to date. It is most likely exploitable over the network when an attacker submits a crafted request to an Envoy‑managed service. Because the flaw revolves around request origin verification, the attack vector can be performed by any party that can reach the Envoy instance over the network.
OpenCVE Enrichment