PT-2026-24401 · Envoy · Envoy

Mandar Jog

·

Publicado

2026-03-10

·

Atualizado

2026-03-12

·

CVE-2026-26330

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy versions prior to 1.34.13 Envoy versions prior to 1.35.8 Envoy versions prior to 1.36.5 Envoy versions prior to 1.37.1
Description Envoy is a high-performance edge/middle/service proxy. A crash may occur in the rate limit filter when the response phase limit with apply on stream done is enabled and the response phase limit request fails. This happens because the inner state of the request phase limit request in the gRPC client is not cleaned up after the request phase is complete, leading to a crash when a second limit request is sent during the response phase and fails. The issue involves the re-use of a safe gRPC client instance for both request and response phases.
Recommendations Update Envoy to version 1.34.13 or later. Update Envoy to version 1.35.8 or later. Update Envoy to version 1.36.5 or later. Update Envoy to version 1.37.1 or later.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-ENVOY-2026-26330
CVE-2026-26330
GHSA-C23C-RP3M-VPG3

Produtos afetados

Envoy