CVE-2026-47778: Envoyproxy Envoy

Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a structural flaw was identified in DefaultCertValidator::verifySubjectAltName where the extracted DNS SAN string is cast to a C-style string using .c_str() before being passed to the Utility::dnsNameMatch() algorithm. If the attacker serves a certificate with a dNSName SAN containing an embedded NUL byte, the helper Utility::generalNameAsString captures the complete string including the NUL. However, when .c_str() evaluates it, implicit conversion to absl::string_view inside dnsNameMatch relies on strlen(), prematurely truncating the evaluation context. Envoy evaluates trucated string against the exact required config_san match and returns true, thereby successfully validating the string with the Nul byte for an upstream routing. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.

Affected products

  • Envoyproxy Envoy: before 1.35.13 (fixed in 1.35.13); from 1.36.0, before 1.36.9 (fixed in 1.36.9); from 1.37.0, before 1.37.5 (fixed in 1.37.5); from 1.38.0, before 1.38.3 (fixed in 1.38.3)

Published 2026-06-26. Last modified 2026-06-29.