VDB
CVE-2026-73547
CVE-2026-73547
PUBLISHED
CVSS 7.5 HIGH
Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check
EPSS 0.55% · 44.5th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.55%
44.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | envoy | 1.39.0, 0, 1.37.0 |
| envoyproxy | envoy |
Timeline
- Aug 26, 2026 CVE Published
- Sep 22, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 3, 2026 EPSS Score
- Oct 7, 2026 EPSS Score
References
- https://github.com/envoyproxy/envoy/commit/064af2e61d0d1c421490d9e3e6e643c5d117ffe4 patch
- https://github.com/envoyproxy/envoy/commit/5f3b8e9b2b8a787a63202d35bb38820f3e9271fe patch
- https://github.com/envoyproxy/envoy/commit/838f8ffd9d7b5217682a22ee33470d4c7afb7e98 patch
- https://github.com/envoyproxy/envoy/commit/c3170d7c747e51bb8254378ea89afc03d3e71929 patch
- https://github.com/envoyproxy/envoy/releases/tag/v1.36.10 article
- https://github.com/envoyproxy/envoy/releases/tag/v1.37.6 article
- https://github.com/envoyproxy/envoy/releases/tag/v1.38.4 article
- https://github.com/envoyproxy/envoy/releases/tag/v1.39.1 article
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-87ph-jqwm-pg6r advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73547 url