Null Pointer Dereference Vulnerability in Envoy Proxy by Envoy Technologies
CVE-2026-47204
What is CVE-2026-47204?
Envoy Proxy is an open source edge and service proxy that facilitates the performance of cloud-native applications. A significant vulnerability has been identified where versions 1.26.0 to 1.35.12, as well as certain versions in the 1.36.x, 1.37.x, and 1.38.x series, are susceptible to a crash when a Connect protocol request is processed through a direct_response route. Specifically, this vulnerability causes the process to terminate due to a null pointer dereference (segmentation fault) triggered by a single unauthenticated HTTP request. This flaw undermines the stability of the Envoy Proxy, making it imperative for users to upgrade to the fixed versions to ensure their deployments remain secure.
Affected Version(s)
envoy >= 1.38.0, < 1.38.3 < 1.38.0, 1.38.3
envoy >= 1.37.0, < 1.37.5 < 1.37.0, 1.37.5
envoy >= 1.36.0, < 1.36.9 < 1.36.0, 1.36.9
