NULL pointer dereference in envoy - CVE-2026-47204
Published: June 24, 2026
envoy
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the envoy.filters.http.grpc_stats filter when processing Connect protocol requests to direct_response routes. A remote user can send a specially crafted HTTP request with a Connect content-type header to cause a denial of service.
Only deployments that use the grpc_stats filter on direct_response routes are vulnerable. No special payload, gRPC client, or protobuf framing is required.