Use-after-free in envoy - CVE-2026-73513
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in common/http/http2 when processing upstream HTTP/2 response trailers without the END_STREAM flag while using oghttp2. A remote attacker can send specially crafted upstream HTTP/2 response headers and trailers to cause a denial of service.
Only the upstream HTTP/2 client path is reachable, and exploitation requires the oghttp2 codec to be enabled.
Affected software
Istio
How to mitigate CVE-2026-73513
Istio - addressed in versions 1.29.7, 1.30.4