Impact
No official description is available, but the title indicates that Envoy’s RBAC engine uses a safe_regex that fails to properly match HTTP header values containing non‑UTF‑8 bytes. This flaw can allow an attacker to craft requests with such header values so that RBAC rules are not evaluated correctly, potentially granting them access to resources they should not be able to reach. The vulnerability therefore enables privilege escalation or unauthorized request execution against protected services.
Affected Systems
The vulnerability is tied to the Envoy proxy. No specific product versions are listed in the data, so any deployment of Envoy that implements RBAC with safe_regex may be affected until a patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact. Exploitation is likely to occur over the network by sending a request with non‑UTF‑8 header values; local privilege is not required. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog, suggesting it is not actively exploited on a large scale yet. Nevertheless, the potential to bypass access controls warrants prompt attention.
OpenCVE Enrichment