PT-2026-52894 · Envoy · Envoy
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Envoy versions 1.37.0 through 1.37.4
Envoy versions 1.38.0 through 1.38.2
Description
Envoy can crash when the
%REQUESTED SERVER NAME(X:Y)% variable is used in the log format and host-related options such as HOST FIRST or SNI FIRST are specified, provided that the specified host header is missing from the request headers.Recommendations
Update Envoy to version 1.37.5.
Update Envoy to version 1.38.3.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Envoy