Improper handling of exceptional conditions in envoy - CVE-2026-26330
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper handling in the global rate limit response phase logic when the response phase limit is enabled and the response phase request fails directly. A remote user can trigger this condition to cause a denial of service.
Exploitation requires the response phase limit to be enabled.