Critical severity10.0NVD Advisory· Published Jun 9, 2022· Updated Jun 17, 2026
CVE-2022-29226
CVE-2022-29226
Description
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4< 1.22.1+ 1 more
- (no CPE)range: < 1.22.1
- cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*range: <1.22.1
Patches
Vulnerability mechanics
References
2- github.com/envoyproxy/envoy/commit/7ffda4e809dec74449ebc330cebb9d2f4ab61360nvdPatchThird Party Advisory
- github.com/envoyproxy/envoy/security/advisories/GHSA-h45c-2f94-prxhnvdThird Party Advisory
News mentions
0No linked articles in our index yet.