---
id: CVE-2020-8664
title: >-
  CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with
  Combined Validation Context
summary: >-
  CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with
  Combined Validation Context. Using the same secret (e.g. trusted CA) across
  many resources together with the combined validation context could lead to the
  “static…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-287
vendor: envoyproxy
product: envoy
affected:
  - envoy <= 1.13.0
published: '2020-03-04'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T21:00:25.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-8664'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2020:0734'
    label: cve@mitre.org
  - url: >-
      https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8
    label: cve@mitre.org
  - url: 'https://www.envoyproxy.io/docs/envoy/v1.13.1/intro/version_history'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0734'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.envoyproxy.io/docs/envoy/v1.13.1/intro/version_history'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.013
epssPercentile: 0.69433
ingestedAt: '2026-10-02T22:33:09.806Z'
---

## Overview

CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) across many resources together with the combined validation context could lead to the “static” part of the validation context to be not applied, even though it was visible in the active config dump.

## Affected

- `envoy <= 1.13.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
