PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48521 envoyproxy CVE debrief

CVE-2026-48521 is a vulnerability in Envoy, an open-source edge and service proxy, that can cause a worker crash when handling HTTP/3 traffic with specific configurations. The issue arises from a null pointer dereference in the ProdClusterManagerFactory::allocateConnPool function. This vulnerability is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

Vendor
envoyproxy
Product
envoy
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-10-05
Advisory published
2026-09-21
Advisory updated
2026-10-05

Who should care

Defenders and administrators using Envoy in their infrastructure, especially those using HTTP/3, should be aware of this vulnerability and take steps to upgrade to a fixed version.

Why it matters

CVE-2026-48521 is a vulnerability in Envoy that can cause worker crashes when handling HTTP/3 traffic. Defenders should prioritize upgrading to fixed versions and review their configurations to prevent potential issues.

  • Potential worker crashes leading to service disruption
  • Need to verify Envoy configurations for HTTP/3 and transport-socket options
  • Upgrade priority to fixed versions of Envoy

Technical summary

The ProdClusterManagerFactory::allocateConnPool function in Envoy dereferences transport_socket_options without checking for null, leading to potential crashes when handling HTTP/3 traffic with specific configurations. This issue is addressed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Affected product deployments should be verified, and defenders should prioritize upgrading to fixed versions while reviewing configurations to prevent potential issues. The vulnerability details indicate that the ProdClusterManagerFactory::allocateConnPool function does not check for null transport_socket_options, which can cause crashes in certain contexts. Upgrading to fixed versions and reviewing configurations can

Defensive priority

Defenders should prioritize upgrading to fixed versions of Envoy, specifically 1.36.10, 1.37.6, 1.38.4, or 1.39.1, to prevent potential crashes. They should also review their Envoy configurations to ensure they are not using HTTP/3 with contexts that supply no transport-socket options.

Recommended defensive actions

  • Upgrade to Envoy version 1.36.10, 1.37.6, 1.38.4, or 1.39.1
  • Review Envoy configurations for HTTP/3 and transport-socket options
  • Monitor Envoy logs for potential crashes
  • Verify affected Envoy deployments in managed environments
  • Confirm exposure and assign an owner for follow-up
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The vulnerability details are based on the official CVE record and the source references provided. The evidence suggests that the vulnerability is related to the handling of HTTP/3 traffic in Envoy, specifically when transport-socket options are not supplied by certain contexts. The fixes are available in specific versions of Envoy.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48521 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48521

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48521 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48521

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.