Memory leak in envoy - CVE-2026-73550
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in Envoy HTTP/2 header handling when processing HTTP/2 requests containing repeated discarded host headers while :authority is present. A remote attacker can send a specially crafted HTTP/2 request to cause a denial of service.
Exploitation requires the runtime guard for HTTP/2 discarded host header behavior to be enabled and relies on ordinary host headers being discarded before request header byte and count limits are charged.
Affected software
Istio
How to mitigate CVE-2026-73550
Istio - addressed in versions 1.29.7, 1.30.4