Junglewise Threat Intelligence

CVE-2026-48706: Envoy heap buffer overflow in TcpStatsdSink

CVE-2026-48706 · Severity: medium · CVSS 5.9 · Published 2026-06-26

Technologies: Envoy Proxy Envoy. Vendors: Envoy Proxy.

Executive brief

Envoy is a popular open-source tool used to manage and secure network traffic for cloud applications. A flaw in how it handles certain monitoring data allows an attacker to crash the service or potentially run unauthorized code by sending specially crafted, extremely long web requests. This could lead to service outages or a compromise of the server's security.

Technical details

A heap write overflow exists in Envoy's TCP StatsD sink (TcpStatsdSink) due to improper buffer management during metric formatting. The flusher reserves a fixed 16KiB memory slice; however, if a single metric name exceeds this capacity, the rotation logic incorrectly allocates another fixed 16KiB slice instead of a larger one, leading to an out-of-bounds write via memcpy. An attacker can trigger this by sending HTTP or gRPC requests with extremely long paths (over 16KiB) if the 'grpc_stats' filter is configured with 'stats_for_all_methods: true'. This can result in a denial-of-service (DoS) or remote code execution (RCE). The issue is fixed in versions 1.35.13, 1.36.9, 1.37.5, and 1.38.3.

Affected products

  • Envoy Proxy Envoy >= 1.34.0, < 1.35.13; >= 1.36.0, < 1.36.9; >= 1.37.0, < 1.37.5; >= 1.38.0, < 1.38.3

Timeline

  • 2026-06-23: advisory: GitHub Security Advisory published
  • 2026-06-26: disclosed: CVE published to NVD

References

Related threats