If the policy stage checks one interpretation and the destination acts on another, an authorised-looking envelope can conceal an action the policy did not approve. Clients need assurance that tool name, arguments and the forwarded message are bound to the same interpretation.

What deployment does this concern?

Component and scope: MCP JSON-RPC parsing in the Envoy AI Gateway / Agent Router project.

Affected versions / scope: < 0.6.0

Vendor remediation: 0.6.0

The affected MCP path interprets a message differently across parsing and forwarding stages. The finding concerns protocol interpretation, not a generic vulnerability in every Envoy deployment.

Vendor response and practical action

The vendor identifies 0.6.0 as patched. Update the affected project and check the deployed MCP path, including policy plugins and any intermediate normalisation.

Treat the vendor notice as the starting point for an applicability decision. Identify the installed artifact and configuration, document whether the prerequisite exists, and assign an owner to any required change. A public advisory does not establish that your installation was exposed or that a managed service shares the same condition.

What clients can learn

Protocol compatibility includes security semantics. Evaluate ambiguous input handling and rejection behaviour as well as successful tool calls. A parser repair should be verified on the exact path that enforces tool policy.

A useful evaluation result connects a named control to evidence from the actual deployment. Keep the provider's statement, your effective configuration and a relevant demonstration together. If the result depends on a feature being disabled or a network being isolated, retain that fact with the version number so a later change triggers review.

Questions to take to your provider

  • Does policy inspect exactly the message sent to the tool?
  • Are ambiguous or duplicate protocol fields rejected consistently?
  • Which gateway release and parser are on the MCP route?
  • Can the operator show a regression result without sharing exploit payloads?

Use the six-page evaluation worksheet to record evidence, ownership and actions. Continue with AI gateway security: protect the boundaries that matter for the wider evaluation context.

Technical detail: evidence and identifier limits

The project repository now uses Agent Router naming. This case does not transfer the finding to the whole Envoy proxy ecosystem.

Evidence label: security advisory. Source-review date: 2026-10-07. Source publication or event date: 2026-05-13. These dates do not change merely because this article is rebuilt.

Primary sources