CVE-2026-48044
EUVD-2026-3982026.06.2026, 18:16
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability has been identified in Envoy's zstd decompressor implementation (ZstdDecompressorImpl). When zstd decompression is enabled, processing a specially crafted, highly compressed zstd payload can lead to massive memory allocation. An attacker can exploit this to cause severe memory exhaustion, potentially resulting in an Out-Of-Memory (OOM) kill and Denial of Service (DoS) for the Envoy proxy. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| envoyproxy | envoy | 1.23.0 ≤ 𝑥 < 1.35.13 |
| envoyproxy | envoy | 1.36.0 ≤ 𝑥 < 1.36.9 |
| envoyproxy | envoy | 1.37.0 ≤ 𝑥 < 1.37.5 |
| envoyproxy | envoy | 1.38.0 ≤ 𝑥 < 1.38.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration