PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73513 envoyproxy CVE debrief

CVE-2026-73513 is a high-severity vulnerability in Envoy, an open-source edge and service proxy. The issue arises from Envoy's optional oghttp2 upstream HTTP/2 codec accepting a response trailer HEADERS frame without END_STREAM, potentially leading to a crash. This vulnerability is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Affected deployments should prioritize upgrading to these versions to mitigate potential process crashes due to improper handling of HTTP/2 codec responses.

Vendor
envoyproxy
Product
envoy
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-28
Advisory published
2026-09-21
Advisory updated
2026-09-28

Who should care

Defenders responsible for Envoy deployments should assess exposure and prioritize upgrading to fixed versions. Monitoring and compensating controls may also be necessary. Security teams and operators managing Envoy instances need to review and verify affected deployments, and plan for remediation. Vulnerability management and platform security teams should track exceptions and retest remediated assets.

Why it matters

CVE-2026-73513 is a high-severity vulnerability in Envoy that requires attention from defenders responsible for Envoy deployments. The vulnerability can lead to potential process crashes and requires verification of affected versions and exposure. Upgrading to fixed versions and monitoring for unusual traffic patterns are necessary.

  • Potential process crashes due to improper handling of HTTP/2 codec responses
  • Need for verification of affected versions and exposure
  • Priority for upgrading to fixed versions of Envoy
  • Monitoring for unusual traffic patterns may be necessary

Technical summary

The vulnerability in Envoy's oghttp2 upstream HTTP/2 codec allows a response trailer HEADERS frame without END_STREAM, potentially leading to a crash. This issue is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. The fixes involve properly handling the END_STREAM flag in the oghttp2 codec to prevent use-after-free errors. Defenders should verify affected versions and exposure, then prioritize upgrading to fixed versions. Monitoring for unusual traffic patterns and implementing compensating controls may also be necessary.

Defensive priority

Defenders should prioritize upgrading to fixed versions of Envoy, specifically 1.36.10, 1.37.6, 1.38.4, or 1.39.1, to mitigate this vulnerability. Additionally, monitoring for unusual traffic patterns and implementing compensating controls may be necessary.

Recommended defensive actions

  • Upgrade to Envoy version 1.36.10, 1.37.6, 1.38.4, or 1.39.1
  • Monitor for unusual traffic patterns
  • Implement compensating controls
  • Review and verify affected Envoy deployments
  • Assess exposure and prioritize remediation
  • Track exceptions and retest remediated assets
  • whoShouldCare

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. GitHub commits and release notes confirm the fixes in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73513 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73513

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73513 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73513

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.