PT-2026-52894 · Envoy · Envoy

·

CVE-2026-47220

·

Published

2026-06-26

·

Updated

2026-06-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy versions 1.37.0 through 1.37.4 Envoy versions 1.38.0 through 1.38.2
Description Envoy can crash when the %REQUESTED SERVER NAME(X:Y)% variable is used in the log format and host-related options such as HOST FIRST or SNI FIRST are specified, provided that the specified host header is missing from the request headers.
Recommendations Update Envoy to version 1.37.5. Update Envoy to version 1.38.3.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ENVOY-2026-47220
CVE-2026-47220
GHSA-J9WH-4QFM-WF2V
OPENSUSE-SU-2026:11141-1

Affected Products

Envoy