Description
No description is available for this CVE.
Published: n/a
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves a use‑after‑free condition in the ext_authz component of Envoy Proxy after it rejects an HTTP request. This flaw can cause the process to access freed memory, potentially leading to a crash or, in a worst‑case scenario, arbitrary code execution if the memory is reused maliciously. The impact is primarily denial of service or memory integrity loss rather than immediate remote code execution.

Affected Systems

Envoy Proxy is affected. No specific vendor‑product or version information is provided by the CNA, so all installations using the ext_authz filter are potentially vulnerable until an official fix is applied.

Risk and Exploitability

With a CVSS score of 5.9 the risk is moderate. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, via network traffic that triggers the filter’s rejection logic. Exploitability requires the attacker to send crafted HTTP requests to the proxied service. The lack of an EPSS score suggests low to moderate exploitation probability, but the potential for causing service outages cannot be ignored.

Generated by OpenCVE AI on September 1, 2026 at 14:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Envoy to the latest stable release that contains the ext_authz use‑after‑free fix
  • If an upgrade is not immediately possible, temporarily remove or disable the ext_authz filter from affected listeners to prevent the trigger condition
  • Monitor Envoy logs and restart rates for sudden crashes or repeated error patterns indicating the vulnerability is being exploited

Generated by OpenCVE AI on September 1, 2026 at 14:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title envoy: envoy: ext_authz use-after-free after rejecting an HTTP request
Weaknesses CWE-416
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-26T13:00:00Z

Links: CVE-2026-50572 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:30:18Z

Weaknesses