{"id":"CVE-2019-9901","details":"Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized path and provide an attacker access beyond the scope provided for by the access control policy.","aliases":["GHSA-2wmf-p7f8-w42h","GHSA-xcx5-93pw-jw2w"],"modified":"2026-08-07T16:35:40.655379Z","published":"2019-04-25T16:29:01.200Z","references":[{"type":"WEB","url":"https://groups.google.com/forum/#%21topic/envoy-announce/VoHfnDqZiAM"},{"type":"ADVISORY","url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-xcx5-93pw-jw2w"},{"type":"ADVISORY","url":"https://www.envoyproxy.io/docs/envoy/v1.9.1/intro/version_history"},{"type":"REPORT","url":"https://github.com/envoyproxy/envoy/issues/6435"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/envoyproxy/envoy","events":[{"introduced":"0"},{"last_affected":"37bfd8ac347955661af695a417492655b21939dc"}],"database_specific":{"cpe":"cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.9.0"}],"source":"CPE_RANGE"}}],"versions":["v1.9.0","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9901.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}