CVE-2026-26309Disclosure(envoyproxy / envoy)

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch envoyproxy envoy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write in Envoy::JsonEscaper::escapeString() can corrupt std::string null-termination, causing undefined behavior and potentially leading to crashes or out-of-bounds reads when the resulting string is later treated as a C-string. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-193

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • envoy

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
envoy

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-10: 3Patch / Workaround · 2026-03-10: 2Technical Details · 2026-03-10: 303-10
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26309 Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write in Envoy::JsonEscaper::escapeString() can cor… https://www.cve.org/CVERecord?id=CVE-2026-26309 ----- Traducción: CVE-2026-26309 Env… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-26309, describing an off‑by‑one write vulnerability in Envoy's JSON escaper that impacts several release versions.

    0000015
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26309 Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write in Envoy::JsonEscaper::escapeString() can cor… https://www.cve.org/CVERecord?id=CVE-2026-26309

    Post summary

    The post discloses a CVE describing an off‑by‑one write in Envoy's JsonEscaper affecting specific versions, with a link to the CVE record and implied patch versions.

    00000191
    56.7K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-26309: Remote off-by-one bug in Envoy’s JSON string escaper can corrupt memory and crash your proxy. Patch to 1.37.1 or the latest stable release now! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-26309 #Envoy #infosec #DevOps

    Post summary

    The tweet announces CVE‑2026‑26309 in Envoy, explains an off‑by‑one memory corruption bug that can crash the proxy, and urges users to patch to 1.37.1 or later.

    0000046
    50 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appenvoyproxyenvoy---
Appenvoyproxyenvoy1.37.0--

Explore more