CVE-2026-6994 | Envoy up to 1.33.0 Query Parameter header_mutation.cc params.add injection (ID 43502 / EUVD-2026-25670)
A vulnerability marked as critical has been reported in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. This manipulation causes injection.
This vulnerability is registered as CVE-2026-6994. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to install a patch to address this issue.