PatchSiren cyber security CVE debrief
CVE-2026-48521 envoyproxy CVE debrief
CVE-2026-48521 is a vulnerability in Envoy, an open-source edge and service proxy, that can cause a worker crash when handling HTTP/3 traffic with specific configurations. The issue arises from a null pointer dereference in the ProdClusterManagerFactory::allocateConnPool function. This vulnerability is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
- Vendor
- envoyproxy
- Product
- envoy
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-10-05
Who should care
Defenders and administrators using Envoy in their infrastructure, especially those using HTTP/3, should be aware of this vulnerability and take steps to upgrade to a fixed version.
Why it matters
CVE-2026-48521 is a vulnerability in Envoy that can cause worker crashes when handling HTTP/3 traffic. Defenders should prioritize upgrading to fixed versions and review their configurations to prevent potential issues.
- Potential worker crashes leading to service disruption
- Need to verify Envoy configurations for HTTP/3 and transport-socket options
- Upgrade priority to fixed versions of Envoy
Technical summary
The ProdClusterManagerFactory::allocateConnPool function in Envoy dereferences transport_socket_options without checking for null, leading to potential crashes when handling HTTP/3 traffic with specific configurations. This issue is addressed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Affected product deployments should be verified, and defenders should prioritize upgrading to fixed versions while reviewing configurations to prevent potential issues. The vulnerability details indicate that the ProdClusterManagerFactory::allocateConnPool function does not check for null transport_socket_options, which can cause crashes in certain contexts. Upgrading to fixed versions and reviewing configurations can
Defensive priority
Defenders should prioritize upgrading to fixed versions of Envoy, specifically 1.36.10, 1.37.6, 1.38.4, or 1.39.1, to prevent potential crashes. They should also review their Envoy configurations to ensure they are not using HTTP/3 with contexts that supply no transport-socket options.
Recommended defensive actions
- Upgrade to Envoy version 1.36.10, 1.37.6, 1.38.4, or 1.39.1
- Review Envoy configurations for HTTP/3 and transport-socket options
- Monitor Envoy logs for potential crashes
- Verify affected Envoy deployments in managed environments
- Confirm exposure and assign an owner for follow-up
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The vulnerability details are based on the official CVE record and the source references provided. The evidence suggests that the vulnerability is related to the handling of HTTP/3 traffic in Envoy, specifically when transport-socket options are not supplied by certain contexts. The fixes are available in specific versions of Envoy.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48521 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48521
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48521 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48521
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/8ef2da8527fcd17388b046c1add4fb47fb5d0868
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/cec4899acf03cf551f28611a5f32385648d95f96
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/e7b4839beef7f43594ce8e94c4563c80db04a8a7
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/f5436f44103fb14cb8ba42a8db0f54a06c98c45a
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.36.10
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.37.6
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.38.4
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.39.1
[email protected] - Release Notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.