CVE-2026-47692Disclosure(envoyproxy / envoy)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header generator emits TLVs beyond the maximum length of 65535 bytes, causing a mismatch between bytes written and the length field in the header. This can result in smuggled bytes on the upstream request. This vulnerability is fixed in 1.35.13, 1.36.9, 1.37.5, and 1.38.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-130

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • envoy

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
envoy

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-26: 2Technical Details · 2026-06-26: 106-26
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-47692 Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header… https://www.cve.org/CVERecord?id=CVE-2026-47692 ----- Traducción: CVE-2026-47692 Env… http://infoflow.cloud`

    Post summary

    The tweet simply posts a link to CVE-2026-47692 for Envoy, offering no substantive details, exploit info, or mitigation guidance.

    0001026
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47692 Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header… https://www.cve.org/CVERecord?id=CVE-2026-47692

    Post summary

    The text provides a basic disclosure for CVE-2026-47692, naming affected Envoy releases and linking to the official CVE record, without offering PoC, exploitation details, or mitigations.

    00000623
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appenvoyproxyenvoy---

Explore more