Description
No description is available for this CVE.
Published: n/a
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap use‑after‑free triggered by HTTP/2 trailers that do not include END_STREAM in Envoy’s oghttp2 implementation. This flaw may lead to memory corruption, potentially causing crashes or unintended behavior in the affected service.

Affected Systems

The affected product is the Envoy proxy, a widely used open‑source HTTP/2 load balancer and service proxy. Specific affected releases are not listed in the provided data, so users should verify whether their current Envoy version is vulnerable by consulting the vendor’s patch notes.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity of the flaw. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting no known public exploitation. The likely attack vector is remote through an HTTP/2 client that can send specially crafted trailers; however, the exact conditions for exploitation are not defined in the supplied information, so the risk is inferred from the nature of the flaw and its severity rating.

Generated by OpenCVE AI on September 1, 2026 at 14:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Envoy to a release that includes the uved fix for the use‑after‑free bug.
  • If an upgrade is not immediately possible, adjust the Envoy configuration to disallow HTTP/2 trailers that omit the END_STREAM flag, thereby preventing the trigger condition.
  • Monitor the Envoy process for abnormal memory usage or crashes and restart the service if signs of instability appear.

Generated by OpenCVE AI on September 1, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title envoy: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free
Weaknesses CWE-416
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-26T13:00:00Z

Links: CVE-2026-73513 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:30:18Z

Weaknesses