Description
No description is available for this CVE.
Published: n/a
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Envoy proxy handling HTTP/3 connections can dereference a null transport socket option during the selection of a connection pool. This null pointer dereference is a CWE‑476 flaw that may cause the process to crash or terminate unexpectedly, leading to a denial of service for the services routed through the affected Envoy instance. The vulnerability is triggered when a client initiates an HTTP/3 session that exercises the connection‑pool selection logic, which may provide the attacker a remote execution path to disrupt the proxy.

Affected Systems

The vulnerability affects the Envoy distributed proxy. No specific product version is listed, so any installation that includes the HTTP/3 connection‑pool selection path may be impacted until a fix is released. The vendor information is provided by the Envoy community in this CVE record.

Risk and Exploitability

The CVSS score is 5.9, indicating medium severity. EPSS is not available and the vulnerability has not been listed in the CISA KEV catalog. The likely attack vector is a remote client sending an HTTP/3 request to the vulnerable Envoy instance. While the flaw does not provide direct code execution, the resulting crash can interrupt service availability and degrade overall system reliability, especially in high‑availability deployments.

Generated by OpenCVE AI on September 1, 2026 at 14:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Envoy to the latest release that includes a fix for the HTTP/3 null dereference.
  • If an upgrade is not immediately possible, disable HTTP/3 support in Envoy to avoid triggering the vulnerable code path.
  • Monitor Envoy logs for crash indications related to transport socket options and configure alerts for abnormal termination.
  • Subscribe to Envoy security advisories to receive patch information as soon as it is released.

Generated by OpenCVE AI on September 1, 2026 at 14:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title envoy: envoy: HTTP/3 null transport socket options dereference during connection-pool selection
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-26T13:00:00Z

Links: CVE-2026-48521 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:30:18Z

Weaknesses