PatchSiren cyber security CVE debrief
CVE-2026-73513 envoyproxy CVE debrief
CVE-2026-73513 is a high-severity vulnerability in Envoy, an open-source edge and service proxy. The issue arises from Envoy's optional oghttp2 upstream HTTP/2 codec accepting a response trailer HEADERS frame without END_STREAM, potentially leading to a crash. This vulnerability is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Affected deployments should prioritize upgrading to these versions to mitigate potential process crashes due to improper handling of HTTP/2 codec responses.
- Vendor
- envoyproxy
- Product
- envoy
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for Envoy deployments should assess exposure and prioritize upgrading to fixed versions. Monitoring and compensating controls may also be necessary. Security teams and operators managing Envoy instances need to review and verify affected deployments, and plan for remediation. Vulnerability management and platform security teams should track exceptions and retest remediated assets.
Why it matters
CVE-2026-73513 is a high-severity vulnerability in Envoy that requires attention from defenders responsible for Envoy deployments. The vulnerability can lead to potential process crashes and requires verification of affected versions and exposure. Upgrading to fixed versions and monitoring for unusual traffic patterns are necessary.
- Potential process crashes due to improper handling of HTTP/2 codec responses
- Need for verification of affected versions and exposure
- Priority for upgrading to fixed versions of Envoy
- Monitoring for unusual traffic patterns may be necessary
Technical summary
The vulnerability in Envoy's oghttp2 upstream HTTP/2 codec allows a response trailer HEADERS frame without END_STREAM, potentially leading to a crash. This issue is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. The fixes involve properly handling the END_STREAM flag in the oghttp2 codec to prevent use-after-free errors. Defenders should verify affected versions and exposure, then prioritize upgrading to fixed versions. Monitoring for unusual traffic patterns and implementing compensating controls may also be necessary.
Defensive priority
Defenders should prioritize upgrading to fixed versions of Envoy, specifically 1.36.10, 1.37.6, 1.38.4, or 1.39.1, to mitigate this vulnerability. Additionally, monitoring for unusual traffic patterns and implementing compensating controls may be necessary.
Recommended defensive actions
- Upgrade to Envoy version 1.36.10, 1.37.6, 1.38.4, or 1.39.1
- Monitor for unusual traffic patterns
- Implement compensating controls
- Review and verify affected Envoy deployments
- Assess exposure and prioritize remediation
- Track exceptions and retest remediated assets
- whoShouldCare
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. GitHub commits and release notes confirm the fixes in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73513 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73513
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73513 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73513
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/0d33268d7d8cdc5c8ffef462e0cceefa56156b72
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/3df69eeee220d6a4088cfdd3be79b55e2e6d3514
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/c4610b6c85d72ed01e014c2a1aba2934a2b774e9
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/commit/e6963c6b64cd62aa8e078ef17c76052b6e33e82b
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.37.6
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.38.4
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/releases/tag/v1.39.1
-
Source reference
Unverified legacy reference
URL: https://github.com/envoyproxy/envoy/security/advisories/GHSA-jjmm-fw8p-crpw
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.