CVE-2026-73549(envoyproxy / envoy)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addresses through addressAsString and Ipv6Instance. The string includes a percent scope identifier that inet_pton cannot parse, causing an exception or abort. Kernel-provided scoped IPv6 destinations in ORIGINAL_DST transparent-proxy deployments, and affected QUIC connection paths, can therefore terminate the process. The relevant scope boundary is that the HTTP use_http_header override rejects scoped addresses earlier; the advisory's crash path requires a kernel-provided original destination or the affected QUIC path. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • envoy

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
envoy

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Referenced assets1 URL
By indicator
Full discourse1 post
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters

    CVE-2026-73549 Envoy: scoped IPv6 handling flaw crashes proxy via malformed address parsing in ORIGINAL_DST and QUIC paths. CVSS 5.3. Patched in 1.36.10, 1.37.6, 1.38.4, 1.39.1. Update now. https://www.valtersit.com/cve/CVE-2026-73549 #CVE #infosec #Envoy #Envoy #CVEALERT #CVE #infosec #Linux #XSS #valtersit #snippet #SysAdmin #cybersecurity #devsecops #devops #developer #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #cybersecurityawareness #cybersecuritynews #cybersecuritytips #python #hacker #kali #ubuntu #debian #docker

    1000036
    1.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appenvoyproxyenvoy---

Explore more