CVE-2026-47207Disclosure(envoyproxy / envoy)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_proc server sends a single gRPC message containing multiple, specially crafted ProcessingResponse messages. This can occur when the first response in the batch causes the gRPC stream object to be destroyed, leading to a use-after-free error when Envoy attempts to process subsequent responses in the same gRPC message. This vulnerability is fixed in 1.35.13, 1.36.9, 1.37.5, and 1.38.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • envoy

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
envoy

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-26: 2Technical Details · 2026-06-26: 206-26
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-47207 Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_… https://www.cve.org/CVERecord?id=CVE-2026-47207 ----- Traducción: CVE-2026-47207 Env… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑47207, noting that certain Envoy versions crash under a specific configuration, but it does not provide a PoC, exploit code, evidence of active use, or patch information.

    0000024
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47207 Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_… https://www.cve.org/CVERecord?id=CVE-2026-47207

    Post summary

    The tweet announces that CVE-2026-47207 causes Envoy to crash on several versions; no exploit or patch details are provided.

    00000638
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appenvoyproxyenvoy---

Explore more