Null Pointer Dereference Vulnerability in Envoy Proxy by Envoy Technologies
CVE-2026-47204

6.5MEDIUM

Key Information:

Vendor

Envoyproxy

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-47204?

Envoy Proxy is an open source edge and service proxy that facilitates the performance of cloud-native applications. A significant vulnerability has been identified where versions 1.26.0 to 1.35.12, as well as certain versions in the 1.36.x, 1.37.x, and 1.38.x series, are susceptible to a crash when a Connect protocol request is processed through a direct_response route. Specifically, this vulnerability causes the process to terminate due to a null pointer dereference (segmentation fault) triggered by a single unauthenticated HTTP request. This flaw undermines the stability of the Envoy Proxy, making it imperative for users to upgrade to the fixed versions to ensure their deployments remain secure.

Affected Version(s)

envoy >= 1.38.0, < 1.38.3 < 1.38.0, 1.38.3

envoy >= 1.37.0, < 1.37.5 < 1.37.0, 1.37.5

envoy >= 1.36.0, < 1.36.9 < 1.36.0, 1.36.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.