Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Wbpcode

#38726of 56,326
7.5Total CVSS
Vulnerabilities · 1
PT-2026-52894
7.5
2026-06-26
Envoy · Envoy · CVE-2026-47220
**Name of the Vulnerable Software and Affected Versions** Envoy versions 1.37.0 through 1.37.4 Envoy versions 1.38.0 through 1.38.2 **Description** Envoy can crash when the `%REQUESTED SERVER NAME(X:Y)%` variable is used in the log format and host-related options such as `HOST FIRST` or `SNI FIRST` are specified, provided that the specified host header is missing from the request headers. **Recommendations** Update Envoy to version 1.37.5. Update Envoy to version 1.38.3.