Executive brief
Envoy is an open-source service proxy that forwards network traffic between applications. When HTTP/3 datagrams and Capsule Protocol are enabled, an attacker can send specially timed HTTP/3 frames that cause the proxy to crash or execute arbitrary code by accessing freed memory. An exploit requires the proxy to process an internal redirect or stream recreation while handling the crafted frames.
Technical details
A heap-use-after-free vulnerability exists in HttpDatagramHandler when Capsule Protocol is enabled for HTTP/3. The handler caches a pointer to RequestDecoder, but stream recreation (via internal redirect) updates the active stream without updating the cached pointer. Subsequent HTTP/3 datagrams call decodeData through the freed decoder, causing invalid virtual dispatch and process crash. The attack requires HTTP/3 and Capsule Protocol to be enabled, plus triggering a stream-recreation path.
Affected products
- Envoy Envoy prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1
Timeline
- 2026-09-21: disclosed
- 2026-09-21: patched: Fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1