VDB

GO-2026-4506

GO-2026-4506 PUBLISHED

opa-envoy-plugin has an Authorization Bypass via Double-Slash Path Misinterpretation in input.parsed_path in github.com/open-policy-agent/opa-envoy-plugin

Affected Products

VendorProductVersions
github.comopen-policy-agent/opa-envoy-plugin0, 0

Timeline

  • Feb 23, 2026 CVE Published
  • Feb 24, 2026 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›