Resource exhaustion in envoy - CVE-2026-48044
Published: June 24, 2026
envoy
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper control of resource consumption in ZstdDecompressorImpl when processing a specially crafted highly compressed zstd payload. A remote attacker can send a specially crafted compressed request body to cause a denial of service.
Only Envoy instances with zstd decompression enabled are vulnerable. The issue can lead to severe memory exhaustion and out-of-memory termination.