CVE-2026-26311Disclosure(envoyproxy / envoy)

LOWCVSS 5.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch envoyproxy envoy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerability in Envoy's HTTP connection manager (FilterManager) that allows for Zombie Stream Filter Execution. This issue creates a "Use-After-Free" (UAF) or state-corruption window where filter callbacks are invoked on an HTTP stream that has already been logically reset and cleaned up. The vulnerability resides in source/common/http/filter_manager.cc within the FilterManager::decodeData method. The ActiveStream object remains valid in memory during the deferred deletion window. If a DATA frame arrives on this stream immediately after the reset (e.g., in the same packet processing cycle), the HTTP/2 codec invokes ActiveStream::decodeData, which cascades to FilterManager::decodeData. FilterManager::decodeData fails to check the saw_downstream_reset_ flag. It iterates over the decoder_filters_ list and invokes decodeData() on filters that have already received onDestroy(). This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • envoy

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
envoy

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-10: 2Patch / Workaround · 2026-03-10: 2Technical Details · 2026-03-10: 203-10
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-26311 Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerability in Envoy's HTTP connection manager (FilterM… https://www.cve.org/CVERecord?id=CVE-2026-26311 ----- Traducción: CVE-2026-26311 Env… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑26311, a logic flaw in Envoy's HTTP connection manager, and notes that versions 1.37.1, 1.36.5, 1.35.8, and 1.34.13 have patched the issue.

    0000020
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26311 Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerability in Envoy's HTTP connection manager (FilterM… https://www.cve.org/CVERecord?id=CVE-2026-26311

    Post summary

    The entry reports a logic vulnerability in Envoy’s HTTP connection manager affecting versions prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, and implies that these are patched in newer releases.

    00000193
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appenvoyproxyenvoy---
Appenvoyproxyenvoy1.37.0--

Explore more