cvedb.io
CVE-2026-26310
MEDIUM · CVSS 5.9
EPSS exploitation probability: 0%
Published 2026-03-10T20:16:36.030 · Last modified 2026-06-17T10:26:04.063

Summary

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::getAddressWithPort with a scoped IPv6 addresses causes a crash. This utility is called in the data plane from the original_src filter and the dns filter. This vulnerability is fixed in 1.37.1, 1.36.5, 1.35.8, and 1.34.13.

Affected products

envoyproxy — envoy

Does this affect you?

Add your gear to cvedb and we'll alert you only when envoyproxy ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.