CVE-2026-47778 Details
Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a structural flaw was identified in DefaultCertValidator::verifySubjectAltName where the extracted DNS SAN string is cast to a C-style string using .c_str() before being passed to the Utility::dnsNameMatch() algorithm. If the attacker serves a certificate with a dNSName SAN containing an embedded NUL byte, the helper Utility::generalNameAsString captures the complete string including the NUL. However, when .c_str() evaluates it, implicit conversion to absl::string_view inside dnsNameMatch relies on strlen(), prematurely truncating the evaluation context. Envoy evaluates trucated string against the exact required config_san match and returns true, thereby successfully validating the string with the Nul byte for an upstream routing. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
A vulnerability exists in Envoy versions prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, where the Default TLS Certificate Validator improperly handles DNS Subject Alternative Names (SANs) containing embedded NUL bytes. This flaw allows an attacker to manipulate certificate validation, potentially bypassing authentication for upstream services. The issue arises because the DNS SAN string is truncated when converted to a C-style string, leading Envoy to incorrectly validate the SAN against configuration requirements. Exploitation of this vulnerability can result in unauthorized authentication to backend services, disrupting assumed transport security.
Update Envoy to version 1.35.13, 1.36.9, 1.37.5, or 1.38.3, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/envoyproxy/envoy/security/advisories/GHSA-f8x4-rw5x-f3r7 | CISA-ADP | ExploitVendor AdvisoryMitigation |
| https://github.com/envoyproxy/envoy/security/advisories/GHSA-f8x4-rw5x-f3r7 | [email protected] | ExploitVendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-158 | Improper Neutralization of Null Byte or NUL Character | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| envoyproxy envoy | < 1.35.13 >= 1.36.0, < 1.36.9 >= 1.37.0, < 1.37.5 >= 1.38.0, < 1.38.3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 27, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | [email protected] |