Beveiligingsadvies

CVE-2026-47220

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-26 18:02:17
Laatst bijgewerkt 2026-07-15 00:49:05
Toegewezen door GitHub_M
CVSS-score 7.5
Status PUBLISHED

Beschrijving

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIRST, it's possible to crash Envoy when the specified host header is missing in the request headers. This vulnerability is fixed in 1.37.5 and 1.38.3.