CVE-2026-48743Disclosure(envoyproxy / envoy)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch envoyproxy envoy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request that is complete at the transport layer (HEADERS with FIN / headers-only close) but still carries a nonzero Content-Length into a complete upstream HTTP/1 request with unresolved body debt. In an HTTP/1 upstream deployment where the origin replies before reading the declared body and keeps the connection reusable, the beginning of the next Envoy-generated upstream request can be consumed as the first request's body. The remaining bytes are then parsed by the origin as a new HTTP/1 request. This was reproduced as a route-bypass/desync: direct /pwn was denied by Envoy, but the second downstream H3 stream received the response for backend-parsed GET /pwn HTTP/1.1. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • envoy

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-06-26)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
envoy

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-24: 1Mentions · 2026-06-26: 2Patch / Workaround · 2026-06-26: 106-2406-26
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-241
Disclosure1
2026-06-262
General1Patch1
Full discourse3 posts
  • Andy Koo@_nd_koo
    Disclosure

    Another small security research moment. CVE-2026-48743, a vulnerability I reported to Envoy Proxy, is now public. https://t.co/gdIlFicaKd

    Post summary

    The tweet announces that CVE-2026-48743, which the author reported to Envoy Proxy, has been publicly disclosed.

    1001611.2K
    480 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-48743 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream … https://www.cve.org/CVERecord?id=CVE-2026-48743 ----- Traducción: CVE-2026-48743 Env… http://infoflow.cloud`

    Post summary

    The text briefly mentions CVE‑2026‑48743 with a link to CVE details, but provides no deeper information on the vulnerability, exploit, or mitigation.

    0001027
    89 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-48743 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream … https://www.cve.org/CVERecord?id=CVE-2026-48743

    Post summary

    The post highlights CVE‑2026-48743 affecting older Envoy releases and notes that newer versions (1.35.11, 1.36.7, 1.37.3, 1.38.1) contain a fix.

    00000892
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appenvoyproxyenvoy---

Explore more