Junglewise Threat Intelligence

CVE-2026-48521: Envoy null pointer dereference in HTTP/3 connection pool allocation

CVE-2026-48521 · Severity: medium · CVSS 5.9 · Published 2026-09-21

Executive brief

Envoy, a cloud-native service proxy, contains a null pointer dereference bug in its HTTP/3 connection pool handling that can be triggered by routine traffic under specific configurations. An attacker or misconfigured deployment can crash an Envoy worker process, causing service disruption. This vulnerability requires HTTP/3 protocol support and specific LoadBalancerContext implementations (used by synthetic, mirror, health-check, or async-client calls) to be present.

Technical details

The ProdClusterManagerFactory::allocateConnPool function dereferences the transport_socket_options pointer without null-checking when selecting an HTTP/3 connection pool. LoadBalancerContext implementations used by synthetic, mirror, health-check, and async-client code paths can return null transport-socket options, triggering a crash. The vulnerability is local to the Envoy process; exploitation requires HTTP/3 enabled and a context supplying no transport-socket options.

Affected products

  • Cloud Native Computing Foundation Envoy Before 1.36.10, 1.37.6, 1.38.4, and 1.39.1

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: Fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1

References