Back

MEDIUM

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled

Published Aug 19, 2026

Description

Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: true` and `.spec.virtualhost.jwtProviders`, Contour does not reject the configuration. Consequently, requests from clients that do not send TLS SNI or send an unrecognized SNI (one that does not match any `HTTPProxy` FQDN) bypass configured JWT verification and are proxied to upstream services without a valid token. This issue is fixed in Contour v1.33.5. Contour now rejects and marks invalid any `HTTPProxy` resources that combine `.spec.virtualhost.tls.enableFallbackCertificate: true` with `.spec.virtualhost.jwtProviders`. Affected resources will receive a status condition with the error reason `TLSIncompatibleFeatures`. As a workaround, do not enable `.spec.virtualhost.tls.enableFallbackCertificate` on `HTTPProxy` resources that also define `.spec.virtualhost.jwtProviders`. Remove one of the two settings to avoid the invalid configuration.

Affected products

Remediation

Red Hat statement

A flaw was found in Contour. When an HTTPProxy combines enableFallbackCertificate with jwtProviders, requests without TLS SNI bypass JWT verification and are proxied without a valid token.

Red Hat mitigation

Upgrade to Contour v1.33.5 or later. As a workaround, do not enable enableFallbackCertificate on HTTPProxy resources that also define jwtProviders.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 19, 2026
Updated Aug 25, 2026
Reserved Jun 3, 2026
CISA Vulnrichment
Updated Aug 25, 2026
NVD
Status Deferred
Modified Sep 18, 2026
Red Hat
Severity Moderate
Public date Jul 2, 2026
GHSA-G3XR-5W5J-W4Q4