PT-2026-102727 · Bitnami · Envoy

Published

2026-09-29

·

Updated

2026-09-29

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addresses through addressAsString and Ipv6Instance. The string includes a percent scope identifier that inet pton cannot parse, causing an exception or abort. Kernel-provided scoped IPv6 destinations in ORIGINAL DST transparent-proxy deployments, and affected QUIC connection paths, can therefore terminate the process. The relevant scope boundary is that the HTTP use http header override rejects scoped addresses earlier; the advisory's crash path requires a kernel-provided original destination or the affected QUIC path. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-ENVOY-2026-73549

Affected Products

Envoy