CVE-2026-73549

Published: Set 21, 2026 Last Modified: Set 23, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,3
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addresses through addressAsString and Ipv6Instance. The string includes a percent scope identifier that inet_pton cannot parse, causing an exception or abort. Kernel-provided scoped IPv6 destinations in ORIGINAL_DST transparent-proxy deployments, and affected QUIC connection paths, can therefore terminate the process. The relevant scope boundary is that the HTTP use_http_header override rejects scoped addresses earlier; the advisory's crash path requires a kernel-provided original destination or the affected QUIC path. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

754

Improper Check for Unusual or Exceptional Conditions

Incomplete
Common Consequences
Security Scopes Affected:
Integrity Availability
Potential Impacts:
Dos: Crash, Exit, Or Restart Unexpected State
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/envoyproxy/envoy/commit/109e5a5b08ad10d99074cefd55a747a16ee6…
https://github.com/envoyproxy/envoy/commit/59b1744a6cb62746db418ac06fc5e359fd25…
https://github.com/envoyproxy/envoy/commit/6e39f4c94deff7a60d382c2d95883e0ea49f…
https://github.com/envoyproxy/envoy/commit/ab2dca2d65b079768230a7c3d825afeefa33…
https://github.com/envoyproxy/envoy/releases/tag/v1.36.10
https://github.com/envoyproxy/envoy/releases/tag/v1.37.6
https://github.com/envoyproxy/envoy/releases/tag/v1.38.4
https://github.com/envoyproxy/envoy/releases/tag/v1.39.1
https://github.com/envoyproxy/envoy/security/advisories/GHSA-jp5f-qr64-c9vw