CVE-2026-48706General(envoyproxy / envoy)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP StatsD sink (TcpStatsdSink), where the thread-local flusher buffer can be overflowed by exceptionally long statistic names (e.g., >16KiB). During formatting, TcpStatsdSink reserves a single contiguous memory slice of 16KiB (FLUSH_SLICE_SIZE_BYTES). If formatting a single metric exceeds the remaining capacity, the flusher initiates a buffer rotation but incorrectly continues to allocate another fixed 16KiB slice. If an attacker can trigger a statistic name longer than 16KiB—for example, by sending an HTTP or gRPC request with an extremely long request path (:path) that is recorded by the grpc_stats filter configured with stats_for_all_methods: true—the flusher will attempt to copy the metric name using memcpy operations beyond the allocated heap buffer boundaries. This leads to a heap write overflow, which can cause immediate denial-of-service (process crash) or potential remote code execution (RCE). This vulnerability is fixed in 1.35.13, 1.36.9, 1.37.5, and 1.38.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • envoy

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
envoy

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-26: 3Technical Details · 2026-06-26: 106-26
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-48706 Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists i… https://www.cve.org/CVERecord?id=CVE-2026-48706 ----- Traducción: CVE-2026-48706 Env… http://infoflow.cloud`

    Post summary

    The post simply references CVE-2026-48706, lists affected Envoy versions, and links to the CVE record, offering no additional details.

    0000026
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48706 Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists i… https://www.cve.org/CVERecord?id=CVE-2026-48706

    Post summary

    CVE-2026-48706 describes a vulnerability present in Envoy versions 1.34.0 through 1.38.3, with the text merely announcing its existence and providing a link to the CVE record, but no PoC, exploits, or patch details are included.

    00000617
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-48706 Heap Buffer Overflow in Envoy TCP StatsD Sink via Long Statistic Names https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48706

    Post summary

    A basic reference to CVE-2026-48706 is provided, noting a heap buffer overflow in Envoy via long statistic names, accompanied only by a link to Vulmon. No exploit details, patches, or active exploitation claims are included.

    00000115
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appenvoyproxyenvoy---

Explore more