PT-2026-24378 · Envoy · Envoy

Finder16

·

Publicado

2026-03-10

·

Atualizado

2026-03-12

·

CVE-2026-26309

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Envoy versions prior to 1.34.13 Envoy versions prior to 1.35.8 Envoy versions prior to 1.36.5 Envoy versions prior to 1.37.1
Description Envoy is a high-performance edge/middle/service proxy. An off-by-one write in the Envoy::JsonEscaper::escapeString() function can corrupt the null-termination of a std::string, potentially leading to crashes or out-of-bounds reads when the resulting string is treated as a C-string.
Recommendations Update to Envoy version 1.34.13 or later. Update to Envoy version 1.35.8 or later. Update to Envoy version 1.36.5 or later. Update to Envoy version 1.37.1 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-ENVOY-2026-26309
CVE-2026-26309
GHSA-56CJ-WGG3-X943

Produtos afetados

Envoy