Improper Check for Unusual or Exceptional Conditions in envoy - CVE-2026-73549
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper check for unusual or exceptional conditions in Utility::copyInternetAddressAndPort() when processing kernel-provided scoped IPv6 destination addresses in ORIGINAL_DST clusters. A remote user can trigger processing of a scoped IPv6 link-local address with a scope ID to cause a denial of service.
This issue is reachable in transparent proxy deployments handling IPv6 link-local traffic, and the crash path requires a real kernel-provided original destination rather than the HTTP header override path.
Affected software
Istio
How to mitigate CVE-2026-73549
Istio - addressed in versions 1.29.7, 1.30.4