Envoy · Envoy · CVE-2026-26310
**Name of the Vulnerable Software and Affected Versions**
Envoy versions prior to 1.37.1
Envoy versions prior to 1.36.5
Envoy versions prior to 1.35.8
Envoy versions prior to 1.34.13
**Description**
Envoy is a high-performance edge/middle/service proxy. Calling the `Utility::getAddressWithPort` function with a scoped IPv6 address can cause a crash. This function is used in the data plane by the original src filter and the dns filter, potentially leading to a denial of service.
**Recommendations**
Update to Envoy version 1.37.1.
Update to Envoy version 1.36.5.
Update to Envoy version 1.35.8.
Update to Envoy version 1.34.13.