Executive brief
Envoy is a proxy that handles network traffic for cloud applications. A flaw in its authorization checking component can cause the proxy to crash when processing rejected requests, potentially disrupting service availability. This occurs under normal production traffic conditions and could be exploited to cause denial of service.
Technical details
The HTTP external-authorization client in Envoy's RawHttpClientImpl retains a stale request callback after a request is rejected, leading to a use-after-free when onSuccess processes the authorization response. The vulnerability affects the ext_authz filter specifically; when the callback owner is destroyed before the response is processed, dereferencing the stale callback pointer causes a crash. Patches are available in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
Affected products
- Envoy Envoy before 1.36.10, before 1.37.6, before 1.38.4, before 1.39.1
Timeline
- 2026-09-21: disclosed