Junglewise Threat Intelligence

CVE-2026-48090: Envoy use-after-free in HTTP OAuth2 filter

CVE-2026-48090 · Severity: medium · CVSS 5.9 · Published 2026-06-26

Technologies: Envoy Proxy Envoy. Vendors: Envoy Proxy.

Executive brief

Envoy is a widely used service proxy that manages network traffic for cloud-native applications. A flaw in its OAuth2 authentication component allows a remote attacker to crash the service by timing network requests in a specific way. This results in a denial-of-service (DoS) condition, potentially disrupting application availability and business operations.

Technical details

A use-after-free (CWE-416) vulnerability exists in the Envoy HTTP OAuth2 filter (envoy.filters.http.oauth2). The filter fails to cancel in-flight asynchronous token exchange requests when a downstream stream is torn down (e.g., via client reset or timeout). If the token response arrives after the stream's destruction, the AsyncClient completion invokes methods on the now-deleted OAuth2Filter object, specifically accessing StreamDecoderFilterCallbacks. This results in undefined behavior, invalid virtual pointer (vptr) access, and worker process crashes. The vulnerability is fixed in versions 1.37.5 and 1.38.3.

Affected products

  • Envoy Proxy Envoy >= 1.37.0, < 1.37.5; >= 1.38.0, < 1.38.3

Timeline

  • 2026-06-23: advisory: GitHub Security Advisory published
  • 2026-06-26: disclosed: CVE published to NVD

References

Related threats