Use of incorrect operator in envoy - CVE-2026-48497
Published: June 24, 2026
envoy
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of incorrect operator in DNS UDP filter when processing a DNS query containing a name 255 octets long. A remote attacker can send a specially crafted DNS query to cause a denial of service.
Exploitation requires that the DNS filter successfully resolve the queried name.