Junglewise Threat Intelligence

CVE-2026-50572: Envoy use-after-free in HTTP external-authorization client

CVE-2026-50572 · Severity: medium · CVSS 5.9 · Published 2026-09-21

Technologies: Envoy. Vendors: Envoy.

Executive brief

Envoy is a proxy that handles network traffic for cloud applications. A flaw in its authorization checking component can cause the proxy to crash when processing rejected requests, potentially disrupting service availability. This occurs under normal production traffic conditions and could be exploited to cause denial of service.

Technical details

The HTTP external-authorization client in Envoy's RawHttpClientImpl retains a stale request callback after a request is rejected, leading to a use-after-free when onSuccess processes the authorization response. The vulnerability affects the ext_authz filter specifically; when the callback owner is destroyed before the response is processed, dereferencing the stale callback pointer causes a crash. Patches are available in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

Affected products

  • Envoy Envoy before 1.36.10, before 1.37.6, before 1.38.4, before 1.39.1

Timeline

  • 2026-09-21: disclosed

References

Related threats