Improper handling of exceptional conditions in envoy - CVE-2026-26330

 

Improper handling of exceptional conditions in envoy - CVE-2026-26330

Published: August 26, 2026


Vulnerability identifier: #VU145841
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-26330
CWE-ID: CWE-755
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper handling in the global rate limit response phase logic when the response phase limit is enabled and the response phase request fails directly. A remote user can trigger this condition to cause a denial of service.

Exploitation requires the response phase limit to be enabled.


Affected software

envoy

How to mitigate CVE-2026-26330

Install security update from vendor's website.

envoy - addressed in versions 1.36.5, 1.37.1

External References

Related Security Bulletins