CVE-2026-73512
Last modified
CVE-2026-73512 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream recreation, including an internal redirect, replaces the ActiveStream and updates EnvoyQuicServerStream but does not update the handler's cached pointer. A subsequent HTTP/3 datagram can call decodeData through the freed decoder, causing invalid virtual dispatch and a process crash. The relevant scope boundary is that hTTP/3 datagrams and Capsule Protocol must be enabled, and the request must enter a stream-recreation path such as an internal redirect. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| envoyproxy | envoy | < 1.36.10; >= 1.37.0, < 1.37.6; >= 1.38.0, < 1.38.4; >= 1.39.0, < 1.39.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-73512?
How severe is CVE-2026-73512?
How do I fix CVE-2026-73512?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73506Oh My Posh is the most customisable and low-latency cross pl…6.1
- CVE-2026-73507Netty is an asynchronous, event-driven network application f…7.5
- CVE-2026-73508Netty is an asynchronous, event-driven network application f…7.5
- CVE-2026-73509OpenList a file list program that supports multiple storage.…7.6
- CVE-2026-7351Race in MHTML in Google Chrome prior to 147.0.7727.138 allow…3.1
- CVE-2026-73511Envoy is an open source edge and service proxy designed for …5.3
- CVE-2026-73513Envoy is an open source edge and service proxy designed for …7.5
- CVE-2026-73514The address_standardizer extension for PostGIS through 3.7.0…8.8
- CVE-2026-73515PostGIS before 3.7.0beta2 contains an out-of-bounds read vul…8.1
- CVE-2026-73519WolfStack before 25.9.2 contains a hard-coded cluster-authen…9.8
- CVE-2026-7352Use after free in Media in Google Chrome on Android prior to…8.3
- CVE-2026-73522COVESA Open1722 through 0.9.2 contains a stack buffer overfl…7.5
Are you affected by CVE-2026-73512?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
