{"id":"CVE-2019-9901","aliases":["GHSA-2wmf-p7f8-w42h","GHSA-xcx5-93pw-jw2w"],"url":"https://o3.security/vulnerability/CVE-2019-9901","summary":"EnvoyProxy Envoy Missing HTTP URL path normalization","details":"Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized path and provide an attacker access beyond the scope provided for by the access control policy.","published":"2019-04-25T16:29:01.200Z","modified":"2026-08-07T16:35:40.655379Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/envoyproxy/envoy","fixedVersion":"1.9.1"}],"fix":null,"references":[{"type":"WEB","url":"https://groups.google.com/forum/#%21topic/envoy-announce/VoHfnDqZiAM"},{"type":"ADVISORY","url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-xcx5-93pw-jw2w"},{"type":"ADVISORY","url":"https://www.envoyproxy.io/docs/envoy/v1.9.1/intro/version_history"},{"type":"REPORT","url":"https://github.com/envoyproxy/envoy/issues/6435"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T16:35:40.655379Z"}}